nerdexam
CompTIA

CAS-003 · Question #1155

Over the last 90 days, many storage services has been exposed in the cloud services environments, and the security team does not have the ability to see is creating these instance. Shadow IT is…

The correct answer is C. Implement a user-behavior system to associate user events and cloud service creation events. The core problem stated is that the security team cannot see WHO is creating unauthorized cloud service instances - the issue is user attribution, not just service discovery. A user behavior analytics (UEBA) system ingests identity-aware events (login activity, API calls…

Enterprise Security Operations

Question

Over the last 90 days, many storage services has been exposed in the cloud services environments, and the security team does not have the ability to see is creating these instance. Shadow IT is creating data services and instances faster than the small security team can keep up with them. The Chief information security Officer (CIASO) has asked the security officer (CISO) has asked the security lead architect to architect to recommend solutions to this problem. Which of the following BEST addresses the problem best address the problem with the least amount of administrative effort?

Options

  • ACompile a list of firewall requests and compare than against interesting cloud services.
  • BImplement a CASB solution and track cloud service use cases for greater visibility.
  • CImplement a user-behavior system to associate user events and cloud service creation events.
  • DCapture all log and feed then to a SIEM and then for cloud service events

How the community answered

(39 responses)
  • A
    15% (6)
  • B
    8% (3)
  • C
    72% (28)
  • D
    5% (2)

Explanation

The core problem stated is that the security team cannot see WHO is creating unauthorized cloud service instances - the issue is user attribution, not just service discovery. A user behavior analytics (UEBA) system ingests identity-aware events (login activity, API calls, console actions) and correlates them with cloud resource provisioning events, directly surfacing which users are spawning shadow IT instances. This addresses the attribution gap with relatively low ongoing administrative overhead once instrumented. Compiling firewall requests manually (A) is labor-intensive and indirect. A CASB (B) provides cloud visibility and policy enforcement but focuses on access and data governance rather than mapping creation events to specific user behavior patterns. Feeding raw logs to a SIEM (D) requires significant tuning, correlation rule development, and ongoing maintenance, representing higher administrative effort.

Topics

#shadow IT#cloud visibility#CASB#user behavior analytics

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice