CV0-003 · Question #241
A company wants to leverage a SaaS provider for its back-office services, and security is paramount. Which of the following solutions should a cloud engineer deploy to BEST meet the security…
The correct answer is D. CASB. A Cloud Access Security Broker (CASB) is the purpose-built solution for enforcing security policies and providing visibility over SaaS application access.
Question
A company wants to leverage a SaaS provider for its back-office services, and security is paramount. Which of the following solutions should a cloud engineer deploy to BEST meet the security requirements?
Options
- AFirewall
- BIPS/IDS
- CProxy gateway
- DCASB
How the community answered
(42 responses)- B5% (2)
- C2% (1)
- D93% (39)
Why each option
A Cloud Access Security Broker (CASB) is the purpose-built solution for enforcing security policies and providing visibility over SaaS application access.
A firewall operates at the network perimeter and controls traffic by port and IP, but lacks the application-layer awareness and SaaS-specific policy controls needed to secure SaaS usage.
An IPS/IDS detects and blocks network-level intrusion attempts but cannot govern SaaS data access, user behavior, or enforce compliance policies within a SaaS application.
A proxy gateway can filter and log web traffic but does not provide the granular SaaS visibility, DLP enforcement, or identity-aware access controls that a CASB delivers.
A CASB sits between enterprise users and SaaS providers to enforce security policies, provide application-layer visibility, prevent data loss, and ensure compliance - capabilities specifically designed for securing third-party SaaS services where the company does not control the underlying infrastructure.
Concept tested: Cloud Access Security Broker for SaaS security
Source: https://learn.microsoft.com/en-us/defender-cloud-apps/what-is-defender-for-cloud-apps
Topics
Community Discussion
No community discussion yet for this question.