156-561 · Question #41
After the cloud acquisition process finishes, Cloud Security Posture Management may begin to manage network security protections. The Network Security module secures access to cloud environments by…
The correct answer is C. Manages Network Security Groups. Managing Network Security Groups (NSGs) is the correct third task because NSGs are the native cloud constructs (in platforms like Azure and AWS) that control inbound/outbound traffic at the network level. CSPM's Network Security module directly reads, evaluates, and manages…
Question
After the cloud acquisition process finishes, Cloud Security Posture Management may begin to manage network security protections. The Network Security module secures access to cloud environments by performing the following tasks: Visualizes Security Policies in cloud environments, controls access to protected cloud assets with short-term dynamic access leases, and:
Options
- AAutomatically Installs Policies
- BDeploys new management resources
- CManages Network Security Groups
- DDeploys new internal cloud resources
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C93% (26)
Explanation
Managing Network Security Groups (NSGs) is the correct third task because NSGs are the native cloud constructs (in platforms like Azure and AWS) that control inbound/outbound traffic at the network level. CSPM's Network Security module directly reads, evaluates, and manages these groups to enforce consistent security policy across cloud environments - alongside the other two listed tasks (policy visualization and dynamic access leases).
Why the distractors are wrong:
- A (Automatically Installs Policies): CSPM tools assess and manage existing policies; they don't autonomously install new ones without human governance oversight - that would undermine the audit/control model CSPM is built around.
- B (Deploys new management resources): Deploying management infrastructure is an operations/provisioning function, not a network security protection task. CSPM manages what exists, not what to build.
- D (Deploys new internal cloud resources): Same reasoning as B - resource deployment is infrastructure provisioning, outside the scope of network security management within CSPM.
Memory tip: Think of the three tasks as See, Control, Manage - Visualize (see policies), dynamic leases (control access), and NSGs (manage the actual network rules). NSGs are the fundamental enforcement layer in cloud networking, so any tool claiming to "secure network access" must manage them directly.
Topics
Community Discussion
No community discussion yet for this question.