nerdexam
Check_Point

156-561 · Question #41

After the cloud acquisition process finishes, Cloud Security Posture Management may begin to manage network security protections. The Network Security module secures access to cloud environments by…

The correct answer is C. Manages Network Security Groups. Managing Network Security Groups (NSGs) is the correct third task because NSGs are the native cloud constructs (in platforms like Azure and AWS) that control inbound/outbound traffic at the network level. CSPM's Network Security module directly reads, evaluates, and manages…

CloudGuard Posture Management (CSPM)

Question

After the cloud acquisition process finishes, Cloud Security Posture Management may begin to manage network security protections. The Network Security module secures access to cloud environments by performing the following tasks: Visualizes Security Policies in cloud environments, controls access to protected cloud assets with short-term dynamic access leases, and:

Options

  • AAutomatically Installs Policies
  • BDeploys new management resources
  • CManages Network Security Groups
  • DDeploys new internal cloud resources

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    93% (26)

Explanation

Managing Network Security Groups (NSGs) is the correct third task because NSGs are the native cloud constructs (in platforms like Azure and AWS) that control inbound/outbound traffic at the network level. CSPM's Network Security module directly reads, evaluates, and manages these groups to enforce consistent security policy across cloud environments - alongside the other two listed tasks (policy visualization and dynamic access leases).

Why the distractors are wrong:

  • A (Automatically Installs Policies): CSPM tools assess and manage existing policies; they don't autonomously install new ones without human governance oversight - that would undermine the audit/control model CSPM is built around.
  • B (Deploys new management resources): Deploying management infrastructure is an operations/provisioning function, not a network security protection task. CSPM manages what exists, not what to build.
  • D (Deploys new internal cloud resources): Same reasoning as B - resource deployment is infrastructure provisioning, outside the scope of network security management within CSPM.

Memory tip: Think of the three tasks as See, Control, Manage - Visualize (see policies), dynamic leases (control access), and NSGs (manage the actual network rules). NSGs are the fundamental enforcement layer in cloud networking, so any tool claiming to "secure network access" must manage them directly.

Topics

#Cloud Security Posture Management#Network Security Groups#Cloud Access Control#Dynamic Access Leases

Community Discussion

No community discussion yet for this question.

Full 156-561 Practice