CASB & Cloud Security Posture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CASB & Cloud Security Posture flashcards as text
In a cloud environment, what does the term 'misconfiguration drift' refer to?
Answer: Cloud resources becoming non-compliant over time due to unmanaged changes
Misconfiguration drift occurs when initially compliant resources accumulate ad-hoc changes that introduce security gaps, requiring continuous CSPM monitoring.
Which feature differentiates a Cloud-Native Application Protection Platform (CNAPP) from a standalone CSPM tool?
Answer: CNAPP integrates workload protection, posture management, and entitlement management in a unified platform
CNAPP unifies CSPM, CWPP (workload protection), CIEM, and container security into a single platform, providing holistic cloud-native application security.
An organization using a multicloud strategy wants consistent security policy enforcement across AWS, Azure, and GCP. Which approach is MOST effective?
Answer: Deploy a cloud-agnostic CSPM with cross-cloud policy templates
A cloud-agnostic CSPM can apply unified policies and provide a single pane of glass for compliance posture across heterogeneous cloud environments.
Which CASB use case is BEST suited for protecting data in a cloud application that does not support proxy-based integration?
Answer: API-based CASB integration using the app's native APIs
When an application doesn't support proxy-based CASB deployment, API integration using the app's native management APIs allows out-of-band data scanning and policy enforcement.
A security engineer notices that a cloud storage bucket has server-side encryption enabled but uses a provider-managed key. What additional control should be recommended to improve data sovereignty?
Answer: Switch to customer-managed encryption keys (CMEK)
Customer-managed encryption keys (CMEK) give the organization control over key lifecycle and the ability to revoke cloud provider access to data if needed.
Which type of attack specifically targets the management plane of a cloud environment to gain unauthorized administrative control?
Answer: Control plane attack targeting cloud IAM and APIs
Control plane attacks target cloud IAM credentials, APIs, and management consoles to gain administrative control, potentially compromising entire cloud accounts.
What does a 'cloud security score' or 'security health score' in a CSPM tool represent?
Answer: An aggregated percentage reflecting compliance with configured security policies across cloud resources
A CSPM security score aggregates pass/fail results across all policy checks into a single percentage, giving teams a quick posture health indicator.