CAS-003 · Question #440
A Chief Information Security Officer (CISO) requests the following external hosted services be scanned for malware, unsecured PII, and healthcare data: - Corporate intranet site - Online storage…
The correct answer is B. CASB. A Cloud Access Security Broker (CASB) is the correct solution for scanning externally hosted cloud services and detecting bulk data downloads. It acts as an intermediary between users and cloud providers to enforce security policies.
Question
A Chief Information Security Officer (CISO) requests the following external hosted services be scanned for malware, unsecured PII, and healthcare data:
- Corporate intranet site
- Online storage application
- Email and collaboration suite
Security policy also is updated to allow the security team to scan and detect any bulk downloads of corporate data from the company's intranet and online storage site. Which of the following is needed to comply with the corporate security policy and the CISO's request?
Options
- APort scanner
- BCASB
- CDLP agent
- DApplication sandbox
- ESCAP scanner
How the community answered
(33 responses)- A6% (2)
- B79% (26)
- C3% (1)
- E12% (4)
Why each option
A Cloud Access Security Broker (CASB) is the correct solution for scanning externally hosted cloud services and detecting bulk data downloads. It acts as an intermediary between users and cloud providers to enforce security policies.
A port scanner identifies open network ports and services; it cannot inspect content stored in cloud applications for malware or sensitive data.
A CASB provides visibility and control over cloud applications such as corporate intranets, online storage, and collaboration suites. It can scan cloud-stored content for malware, unsecured PII, and regulated data like PHI, and can detect anomalous activity such as bulk downloads through behavioral analysis - addressing all stated requirements in a single platform.
A DLP agent is installed on endpoints to monitor local data in motion or at rest; it does not have visibility into externally hosted cloud services.
An application sandbox executes unknown code in an isolated environment to detect malware; it is not designed to scan cloud storage or detect bulk data transfers.
A SCAP scanner audits system configurations against compliance benchmarks; it does not scan cloud service content or detect data exfiltration.
Concept tested: CASB for cloud service security monitoring and DLP
Source: https://www.cisa.gov/sites/default/files/publications/CISA_Cloud_Security_Best_Practices.pdf
Topics
Community Discussion
No community discussion yet for this question.