Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A company is implementing a cloud access security broker (CASB) solution. What is the primary security challenge that CASBs are designed to address in cloud environments?
- AManaging physical access to cloud provider data centers.
- BEnforcing security policies and governance across multiple cloud services.
- CAutomating vulnerability scanning for custom-developed applications.
- DProtecting on-premises data centers from external attacks.
Show answer & explanationAnswer & explanation
Correct answer: B. Enforcing security policies and governance across multiple cloud services.
CASBs act as a security policy enforcement point between cloud service consumers and cloud service providers. Their primary role is to extend an organization's security policies from their on-premises infrastructure to the cloud, addressing challenges like shadow IT, data loss prevention, and compliance.
Why the other options are wrong
- A. Physical access is the responsibility of the cloud provider, not typically managed by a CASB.
- C. While some CASBs may offer integration, their core function is not solely vulnerability scanning for custom apps.
- D. This is a traditional perimeter security concern, not the primary focus of CASBs in the cloud.
Cloud Access Security Broker (CASB)
A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed.
- Addresses cloud security gaps and shadow IT.
- Enforces data loss prevention (DLP), access control, encryption.
- Provides visibility into cloud usage and compliance.
Memory trick: CASB is like a 'C'loud 'A'ccess 'S'ecurity 'B'ouncer for your data.