Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
A cybersecurity team is concerned about the risk of 'shadow IT' within their organization, specifically employees using unsanctioned cloud applications to store and share company data. They need a solution that can discover these unsanctioned applications, assess their risk, enforce security policies, and detect sensitive data exfiltration to them. Which cloud security technology is designed for this purpose?
- ACloud Security Posture Management (CSPM)
- BCloud Workload Protection Platform (CWPP)
- CNetwork Intrusion Detection System (NIDS)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is specifically designed to address shadow IT by discovering unsanctioned cloud applications, monitoring user activity, enforcing security policies, and preventing sensitive data from being uploaded to or downloaded from these services.
Why the other options are wrong
- A. CSPM monitors cloud infrastructure configurations for misconfigurations and compliance, not shadow IT applications.
- B. CWPP focuses on securing cloud workloads (VMs, containers), not identifying or controlling unsanctioned SaaS applications.
- C. NIDS monitors network traffic for malicious activity but doesn't specifically identify unsanctioned cloud app usage or enforce policies on them.
Cloud Access Security Broker (CASB)
A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud resources are accessed.
- Addresses shadow IT, data security, threat protection, and compliance
- Can enforce policies on sanctioned and unsanctioned cloud apps
- Operates as a proxy, API integration, or log-based
Memory trick: CASB: Controls All Shadowy Business.