CASB & Cloud Security Posture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CASB & Cloud Security Posture flashcards as text
What does the CIS Cloud Security Benchmark primarily provide?
Answer: Prescriptive configuration guidelines for securing cloud environments
CIS Benchmarks offer prescriptive, consensus-based configuration best practices that CSPM tools use as baseline checks for cloud resource hardening.
An attacker exfiltrates data from a cloud environment by encoding it in DNS queries to an external resolver. Which control would MOST effectively detect this?
Answer: DNS query logging and anomaly detection
DNS exfiltration bypasses traditional network controls, so logging DNS queries and analyzing volume/entropy anomalies is the most effective detection approach.
Which CASB control mode allows an administrator to warn users about policy violations and let them proceed, while logging their decision?
Answer: Coaching/justify mode
Coaching (or justify) mode presents a policy warning and requires users to provide a business justification before proceeding, balancing security with productivity.
A CSPM tool identifies that multi-factor authentication is not enforced for privileged cloud console accounts. Under which compliance framework would this most likely be cited as a finding?
Answer: All of the above frameworks address MFA for privileged accounts
PCI DSS, HIPAA, and SOC 2 all require strong authentication controls for privileged access, making this a cross-framework compliance gap.
Which cloud security concept describes the practice of deploying security controls as code within CI/CD pipelines to catch misconfigurations before deployment?
Answer: Shift-left security
Shift-left security integrates security testing and policy checks early in the software development lifecycle, preventing misconfigurations from reaching production.
What is the purpose of a Cloud Infrastructure Entitlement Management (CIEM) solution?
Answer: Discover and right-size excessive permissions across cloud identities
CIEM solutions analyze identity permissions across cloud environments to identify and remediate over-privileged accounts, service principals, and roles.
A company's CASB reports high usage of an unapproved file-sharing app. The security team decides to formally sanction it with DLP controls rather than block it. What is this approach called?
Answer: Risk acceptance with compensating controls
Formally approving a previously shadow IT application and applying compensating controls (like DLP) is a documented risk acceptance decision.