nerdexam
CompTIA

CAS-003 · Question #440

A Chief Information Security Officer (CISO) requests the following external hosted services be scanned for malware, unsecured PII, and healthcare data: - Corporate intranet site - Online storage…

The correct answer is B. CASB. A Cloud Access Security Broker (CASB) is the correct solution for scanning externally hosted cloud services and detecting bulk data downloads. It acts as an intermediary between users and cloud providers to enforce security policies.

Technical Integration of Enterprise Security

Question

A Chief Information Security Officer (CISO) requests the following external hosted services be scanned for malware, unsecured PII, and healthcare data:

  • Corporate intranet site
  • Online storage application
  • Email and collaboration suite

Security policy also is updated to allow the security team to scan and detect any bulk downloads of corporate data from the company's intranet and online storage site. Which of the following is needed to comply with the corporate security policy and the CISO's request?

Options

  • APort scanner
  • BCASB
  • CDLP agent
  • DApplication sandbox
  • ESCAP scanner

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    79% (26)
  • C
    3% (1)
  • E
    12% (4)

Why each option

A Cloud Access Security Broker (CASB) is the correct solution for scanning externally hosted cloud services and detecting bulk data downloads. It acts as an intermediary between users and cloud providers to enforce security policies.

APort scanner

A port scanner identifies open network ports and services; it cannot inspect content stored in cloud applications for malware or sensitive data.

BCASBCorrect

A CASB provides visibility and control over cloud applications such as corporate intranets, online storage, and collaboration suites. It can scan cloud-stored content for malware, unsecured PII, and regulated data like PHI, and can detect anomalous activity such as bulk downloads through behavioral analysis - addressing all stated requirements in a single platform.

CDLP agent

A DLP agent is installed on endpoints to monitor local data in motion or at rest; it does not have visibility into externally hosted cloud services.

DApplication sandbox

An application sandbox executes unknown code in an isolated environment to detect malware; it is not designed to scan cloud storage or detect bulk data transfers.

ESCAP scanner

A SCAP scanner audits system configurations against compliance benchmarks; it does not scan cloud service content or detect data exfiltration.

Concept tested: CASB for cloud service security monitoring and DLP

Source: https://www.cisa.gov/sites/default/files/publications/CISA_Cloud_Security_Best_Practices.pdf

Topics

#CASB#cloud security#DLP#PII scanning

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice