โ† All CCP Flashcard Decks

CASB & Cloud Security Posture Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CASB & Cloud Security Posture flashcards as text
  1. What does the CIS Cloud Security Benchmark primarily provide?

    Answer: Prescriptive configuration guidelines for securing cloud environments

    CIS Benchmarks offer prescriptive, consensus-based configuration best practices that CSPM tools use as baseline checks for cloud resource hardening.

  2. An attacker exfiltrates data from a cloud environment by encoding it in DNS queries to an external resolver. Which control would MOST effectively detect this?

    Answer: DNS query logging and anomaly detection

    DNS exfiltration bypasses traditional network controls, so logging DNS queries and analyzing volume/entropy anomalies is the most effective detection approach.

  3. Which CASB control mode allows an administrator to warn users about policy violations and let them proceed, while logging their decision?

    Answer: Coaching/justify mode

    Coaching (or justify) mode presents a policy warning and requires users to provide a business justification before proceeding, balancing security with productivity.

  4. A CSPM tool identifies that multi-factor authentication is not enforced for privileged cloud console accounts. Under which compliance framework would this most likely be cited as a finding?

    Answer: All of the above frameworks address MFA for privileged accounts

    PCI DSS, HIPAA, and SOC 2 all require strong authentication controls for privileged access, making this a cross-framework compliance gap.

  5. Which cloud security concept describes the practice of deploying security controls as code within CI/CD pipelines to catch misconfigurations before deployment?

    Answer: Shift-left security

    Shift-left security integrates security testing and policy checks early in the software development lifecycle, preventing misconfigurations from reaching production.

  6. What is the purpose of a Cloud Infrastructure Entitlement Management (CIEM) solution?

    Answer: Discover and right-size excessive permissions across cloud identities

    CIEM solutions analyze identity permissions across cloud environments to identify and remediate over-privileged accounts, service principals, and roles.

  7. A company's CASB reports high usage of an unapproved file-sharing app. The security team decides to formally sanction it with DLP controls rather than block it. What is this approach called?

    Answer: Risk acceptance with compensating controls

    Formally approving a previously shadow IT application and applying compensating controls (like DLP) is a documented risk acceptance decision.