CASB & Cloud Security Posture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CASB & Cloud Security Posture flashcards as text
Which CASB deployment mode inspects traffic by sitting inline between users and cloud services in real time?
Answer: Forward proxy mode
Forward proxy mode intercepts all cloud-bound traffic inline, enabling real-time inspection and control before requests reach the cloud service.
A CSPM tool flags a misconfigured S3 bucket as 'publicly readable.' What is the FIRST remediation step?
Answer: Remove public access permissions and audit bucket contents
Removing public access permissions stops exposure immediately, while auditing contents determines if a data breach notification is required.
Which cloud security concept ensures that the permissions granted to an identity are limited to only what is required for its tasks?
Answer: Principle of least privilege
The principle of least privilege restricts identities to the minimum permissions needed, reducing the blast radius of credential compromise.
An organization wants to prevent users from uploading sensitive files to personal cloud storage accounts while allowing corporate accounts. Which CASB feature best addresses this?
Answer: Tenant restriction
Tenant restriction enforces access only to approved corporate tenants of a cloud service, blocking personal account usage on managed devices.
In the shared responsibility model for SaaS, which layer is the customer always responsible for securing?
Answer: User access and data
In SaaS, the provider manages infrastructure through application code; the customer retains responsibility for user access controls and the data they store.
A CASB API integration can scan existing data at rest in a cloud application. What is the primary limitation of this approach compared to inline proxying?
Answer: It cannot enforce real-time blocking of uploads
API-based CASB discovers and classifies data already stored in the cloud but cannot block uploads in real time because it operates out-of-band.
Which metric is MOST useful when evaluating the risk score of a cloud application in a shadow IT discovery report?
Answer: Amount of data uploaded by internal users
The volume of data uploaded by internal users directly quantifies the potential data exposure risk associated with unsanctioned cloud usage.