Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A financial institution is migrating its legacy applications to a multi-cloud environment. They require a robust solution to enforce consistent security policies, detect shadow IT, and prevent data leakage across all cloud services, including SaaS, PaaS, and IaaS. Which cloud security technology is specifically designed to address these comprehensive requirements?
- ACloud Workload Protection Platform (CWPP)
- BCloud Security Posture Management (CSPM)
- CSecurity Information and Event Management (SIEM)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Access Security Broker (CASB)
CASBs are specifically designed to act as policy enforcement points between cloud service consumers and providers, offering capabilities like shadow IT discovery, data loss prevention (DLP), and granular access control across various cloud service models (SaaS, PaaS, IaaS).
Why the other options are wrong
- A. CWPP focuses on runtime protection of workloads (VMs, containers, serverless), not comprehensive policy enforcement across SaaS or shadow IT detection.
- B. CSPM focuses on identifying misconfigurations and compliance gaps in cloud infrastructure, not shadow IT or data leakage across all cloud service types.
- C. SIEMs collect and analyze logs for threat detection and incident response, but don't enforce policies or detect shadow IT directly across cloud services.
Cloud Access Security Broker (CASB)
A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed.
- Offers visibility into cloud app usage (shadow IT detection).
- Enforces data loss prevention (DLP) policies.
- Provides threat protection and access control for cloud services.
Memory trick: CASB is the cloud's security broker, watching all your cloud interactions.