Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A cloud security engineer needs to implement a solution to automatically identify and remediate misconfigurations in cloud resources, such as open S3 buckets, overly permissive IAM policies, and unencrypted databases. This solution should continuously monitor the cloud environment and provide actionable insights. Which type of cloud security tool is best suited for this purpose?

  1. ACloud Workload Protection Platform (CWPP)
  2. BCloud Security Posture Management (CSPM)
  3. CSecurity Information and Event Management (SIEM)
  4. DCloud Access Security Broker (CASB)
Show answer & explanation

Correct answer: B. Cloud Security Posture Management (CSPM)

Cloud Security Posture Management (CSPM) tools are designed to continuously monitor cloud environments for misconfigurations, compliance violations, and security risks. They provide visibility into the security posture of cloud resources and often offer automated remediation capabilities.

Why the other options are wrong

  • A. CWPP focuses on securing workloads (VMs, containers, serverless functions) at runtime, not primarily on identifying and remediating infrastructure misconfigurations.
  • C. SIEM aggregates and analyzes logs from various sources for threat detection, but doesn't inherently focus on continuous posture management and misconfiguration remediation.
  • D. CASB focuses on securing access to and usage of cloud applications, often for SaaS, and is not primarily for infrastructure misconfiguration detection.

Cloud Security Posture Management (CSPM)

A category of cloud security tools that continuously monitor and improve the security posture of cloud infrastructure.

  • Identifies misconfigurations, compliance violations, and risks.
  • Provides visibility and actionable remediation steps.
  • Applies to IaaS and PaaS components.

Memory trick: CSPM: Constantly Scans for Posture Misconfigurations.

More Cloud Security questions