Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A cloud security engineer needs to implement a solution that automatically identifies and remediates misconfigurations in their AWS environment, such as S3 buckets with public access or security groups allowing unrestricted SSH access (0.0.0.0/0). The solution should continuously monitor the environment and provide compliance reporting. Which specialized cloud security tool is designed for this purpose?
- ACloud Security Posture Management (CSPM)
- BCloud Access Security Broker (CASB)
- CSecurity Information and Event Management (SIEM)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Security Posture Management (CSPM)
Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing automated detection and often remediation capabilities.
Why the other options are wrong
- B. CASBs focus on cloud service access, data governance, and threat protection for SaaS/PaaS, not infrastructure misconfigurations.
- C. SIEM aggregates and analyzes logs for security events, but does not primarily focus on identifying and remediating infrastructure misconfigurations.
- D. DLP prevents sensitive data from leaving an organization's control, not for infrastructure misconfiguration detection.
Cloud Security Posture Management (CSPM)
A category of security tools designed to continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation capabilities.
- Detects and remediates misconfigurations (e.g., public S3 buckets, overly permissive security groups).
- Provides continuous compliance monitoring against regulatory standards.
- Offers a centralized view of cloud security posture.
Memory trick: CSPM is your cloud's 'C'onfiguration 'S'ecurity 'P'atrol 'M'onitor.