Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A cloud security engineer needs to implement a solution that automatically detects and remediates misconfigurations in their AWS environment, such as publicly exposed S3 buckets, overly permissive IAM policies, or unencrypted EBS volumes. Which cloud security tool category is purpose-built for this type of continuous posture management?

  1. ASecurity Information and Event Management (SIEM)
  2. BCloud Access Security Broker (CASB)
  3. CCloud Security Posture Management (CSPM)
  4. DCloud Workload Protection Platform (CWPP)
Show answer & explanation

Correct answer: C. Cloud Security Posture Management (CSPM)

Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor cloud environments for misconfigurations, compliance violations, and insecure settings, and often provide automated remediation capabilities.

Why the other options are wrong

  • A. SIEMs aggregate logs for threat detection, but don't directly identify or remediate infrastructure misconfigurations.
  • B. CASBs focus on cloud service usage, data loss prevention, and shadow IT, not infrastructure misconfigurations.
  • D. CWPP focuses on protecting running workloads (VMs, containers) at runtime from threats, not identifying misconfigurations.

Cloud Security Posture Management (CSPM)

A category of security tools that continuously monitor cloud environments to identify and remediate misconfigurations, compliance violations, and security risks in cloud infrastructure.

  • Focuses on 'build-time' and 'deploy-time' security.
  • Helps enforce security best practices and regulatory compliance.
  • Often includes automated remediation capabilities.

Memory trick: CSPM: Cloud's posture manager, checks if everything is standing straight.

More Cloud Security questions