Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A cloud security engineer needs to implement a solution that continuously monitors their cloud resources for security misconfigurations and compliance violations against industry benchmarks and regulatory standards. Which type of cloud security technology is specifically designed for this purpose?
- ACloud Workload Protection Platform (CWPP)
- BCloud Security Posture Management (CSPM)
- CSecurity Information and Event Management (SIEM)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Security Posture Management (CSPM)
CSPM tools continuously monitor cloud environments for security misconfigurations, compliance violations, and risks. They help organizations maintain a strong security posture by identifying and often remediating issues against defined policies and regulatory frameworks.
Why the other options are wrong
- A. CWPPs focus on protecting workloads (VMs, containers, serverless functions) from threats, not primarily misconfigurations.
- C. SIEMs collect and analyze security logs and events from various sources for threat detection, but are not primarily for posture management.
- D. CASBs focus on data security, threat protection, and policy enforcement for cloud applications, not broad posture management.
Cloud Security Posture Management (CSPM)
A category of security tools that continuously monitor cloud environments for security misconfigurations, compliance violations, and overall security posture risks.
- Identifies misconfigured resources (e.g., open S3 buckets, overly permissive IAM roles).
- Checks against industry benchmarks (CIS) and regulatory standards (HIPAA, PCI DSS).
- Provides visibility, risk assessment, and often automated remediation.
Memory trick: CSPM is like a 'C'loud 'S'ecurity 'P'osture 'M'onitor, checking if everything is in place.