Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
A cybersecurity team is concerned about the risk of 'shadow IT' within their organization, where employees are using unapproved cloud services for business operations. Which cloud security best practice is most effective in mitigating this risk?
- AImplementing strong data encryption at rest
- BConducting regular penetration testing
- CEnforcing the Principle of Least Privilege
- DEstablishing a robust Cloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: D. Establishing a robust Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) provides visibility into cloud service usage, including unapproved 'shadow IT' applications, and can enforce security policies, block access to unsanctioned apps, and prevent data exfiltration, directly addressing the risks of shadow IT.
Why the other options are wrong
- A. Data encryption at rest protects data in sanctioned storage but doesn't address the discovery or control of unsanctioned services.
- B. Penetration testing identifies vulnerabilities in known systems, but doesn't discover or control shadow IT.
- C. Least privilege is an access control principle for sanctioned systems, not for discovering or managing unsanctioned ones.
Shadow IT Mitigation
The process of identifying, monitoring, and controlling the use of unauthorized or unapproved cloud services and applications by employees within an organization.
- Shadow IT poses security risks due to lack of oversight.
- CASBs are key tools for discovery and control.
- Requires policy enforcement, education, and technical controls.
Memory trick: CASB is like a 'ghostbuster' for Shadow IT, making unseen apps visible and controllable.