CAS-003 · Question #305
Security policies that are in place at an organization prohibit USB drives from being utilized across the entire enterprise, with adequate technical controls in place to block them. As a way to…
The correct answer is B. Deploying a CASB. Tests knowledge of CASB as the correct control for monitoring and governing shadow IT cloud service usage.
Question
Security policies that are in place at an organization prohibit USB drives from being utilized across the entire enterprise, with adequate technical controls in place to block them. As a way to still be able to work from various locations on different computing resources, several sales staff members have signed up for a web-based storage solution without the consent of the IT department. However, the operations department is required to use the same service to transmit certain business partner documents. Which of the following would BEST allow the IT department to monitor and control this behavior?
Options
- AEnabling AAA
- BDeploying a CASB
- CConfiguring an NGFW
- DInstalling a WAF
- EUtilizing a vTPM
How the community answered
(33 responses)- A3% (1)
- B70% (23)
- C15% (5)
- D9% (3)
- E3% (1)
Why each option
Tests knowledge of CASB as the correct control for monitoring and governing shadow IT cloud service usage.
AAA provides a framework for authenticating and accounting for access to network resources but lacks the application-layer intelligence to identify and selectively control access to specific cloud storage services based on user or department.
A Cloud Access Security Broker (CASB) sits inline between users and cloud service providers, delivering visibility, compliance enforcement, and granular policy control over cloud applications. It can simultaneously block unauthorized cloud storage use by sales staff while permitting sanctioned use by the operations department, directly addressing the dual requirement of monitoring and controlling access to the same cloud service with department-level granularity.
An NGFW can block traffic to specific domains or IPs but cannot apply user-level or department-level policy granularity to distinguish permitted versus prohibited usage of the same cloud service.
A WAF protects internally hosted web applications from inbound attacks and does not monitor or control employees' outbound access to external cloud storage platforms.
A vTPM is a virtualized hardware security module used for platform integrity attestation and cryptographic key storage, and has no capability to monitor or control cloud service access.
Concept tested: CASB for shadow IT cloud service governance
Source: https://learn.microsoft.com/en-us/defender-cloud-apps/what-is-defender-for-cloud-apps
Topics
Community Discussion
No community discussion yet for this question.