Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A company requires strict adherence to data residency regulations, mandating that certain categories of sensitive customer data must not be stored or processed outside a specific geographic region. The company uses cloud-based applications (SaaS) extensively. Which content security technology is best suited to enforce these data residency policies and prevent unauthorized data transfers to non-compliant cloud storage locations?

  1. AIntrusion Prevention System (IPS)
  2. BSecure Web Gateway (SWG)
  3. CCloud Access Security Broker (CASB)
  4. DNetwork Access Control (NAC)
Show answer & explanation

Correct answer: C. Cloud Access Security Broker (CASB)

A Cloud Access Security Broker (CASB) is specifically designed to enforce security policies for cloud applications. It can monitor and control data movement to and from cloud services, making it ideal for enforcing data residency requirements and preventing sensitive data from being stored in non-compliant regions.

Why the other options are wrong

  • A. IPS detects and prevents network intrusions, not data residency policy enforcement in cloud apps.
  • B. SWGs primarily control web browsing to and from the internet, not specifically data residency within cloud applications.
  • D. NAC controls network access based on device posture and user identity, not data residency within cloud applications.

Cloud Access Security Broker (CASB)

A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud resources are accessed.

  • Provides visibility, data security, threat protection, and compliance for cloud apps.
  • Enforces data residency, DLP, and access control policies for SaaS, PaaS, and IaaS.
  • Can operate in proxy, API, or log-based modes.

Memory trick: CASB Controls Cloud Access, Compliance Covered.

More Content Security questions