CV0-003 · Question #300
The CASB report indicates several unsanctioned SaaS applications are being used in an organization. Which of the following is the MOST likely cause?
The correct answer is B. Shadow IT. Unsanctioned SaaS usage detected by a CASB is the defining symptom of Shadow IT - employees adopting cloud services without IT department knowledge or approval.
Question
The CASB report indicates several unsanctioned SaaS applications are being used in an organization. Which of the following is the MOST likely cause?
Options
- AVPN bypass
- BShadow IT
- CWeb proxy bypass
- DCAB approval
How the community answered
(37 responses)- A3% (1)
- B89% (33)
- C3% (1)
- D5% (2)
Why each option
Unsanctioned SaaS usage detected by a CASB is the defining symptom of Shadow IT - employees adopting cloud services without IT department knowledge or approval.
VPN bypass is a technique for circumventing VPN controls and does not describe the organizational behavior of using unauthorized applications.
Shadow IT describes the use of IT systems, software, or cloud services within an organization without explicit IT authorization or oversight. When a CASB report surfaces unsanctioned SaaS applications, it is identifying exactly this phenomenon - users bypassing formal procurement and approval workflows to use cloud services they find convenient, which is the textbook definition of Shadow IT.
Web proxy bypass is a method of evading content filtering controls, not a term for the broader pattern of unauthorized SaaS adoption.
CAB (Change Advisory Board) approval is a formal change management process, not a security concept related to unauthorized application usage.
Concept tested: Shadow IT detection using CASB
Source: https://www.cisa.gov/sites/default/files/publications/Cloud_Security_Technical_Reference_Architecture.pdf
Topics
Community Discussion
No community discussion yet for this question.