Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium
A security team needs to implement a solution that provides real-time visibility into application usage, user behavior, and potential threats within SaaS applications like Office 365 and Salesforce. The solution must also enforce data loss prevention policies for data stored and shared within these cloud applications. Which content security technology is designed for this specific purpose?
- AEndpoint Detection and Response (EDR)
- BCloud Access Security Broker (CASB)
- CSecure Web Gateway (SWG)
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) specifically addresses the security challenges of SaaS applications. It provides visibility into cloud app usage, enforces policies (including DLP) for data in the cloud, and protects against threats arising from cloud services.
Why the other options are wrong
- A. EDR focuses on endpoint security, detecting and responding to threats on devices, not on securing data and activity within cloud applications.
- C. An SWG primarily secures web browsing traffic and applies policies to internet access, but it typically does not provide deep visibility or DLP for data *within* specific SaaS applications.
- D. An IPS primarily detects and prevents network-based attacks and does not have the context or capabilities to monitor or enforce policies within SaaS applications.
Cloud Access Security Broker (CASB)
A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed.
- Provides visibility into cloud app usage.
- Enforces data loss prevention (DLP) for cloud data.
- Protects against cloud-based threats and ensures compliance.
Memory trick: CASB: Cloud Apps Secured, Accounted, and Brokered.