← All CCP Flashcard Decks

CASB & Cloud Security Posture Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 CASB & Cloud Security Posture flashcards as text
  1. A CASB solution detects that a user uploaded a file containing 50 credit card numbers to a personal Dropbox account. Under which regulation is this most likely a reportable incident?

    Answer: PCI DSS

    Credit card numbers are payment card data governed by PCI DSS, and unauthorized storage of cardholder data outside approved environments triggers incident response requirements.

  2. Which cloud security architecture pattern uses a dedicated cloud account or subscription exclusively for centralizing logging, security monitoring, and compliance tools?

    Answer: Hub-and-spoke security account model

    The hub-and-spoke model places shared security services (SIEM, CSPM, logging) in a central 'hub' account, with workload accounts ('spokes') streaming data to it.

  3. When evaluating a SaaS vendor's cloud security posture, which document provides the most authoritative evidence of their internal control effectiveness?

    Answer: SOC 2 Type II audit report from an independent auditor

    A SOC 2 Type II report, produced by an independent auditor over a testing period, provides evidence that controls were operating effectively—not just designed correctly.

  4. Which CASB capability specifically addresses identifying and classifying sensitive data already stored within sanctioned cloud applications?

    Answer: Data-at-rest scanning via API integration

    Data-at-rest scanning uses cloud application APIs to crawl and classify existing stored content, identifying sensitive data that may have been uploaded before CASB was deployed.

  5. An organization's CSPM tool generates hundreds of daily findings. What is the BEST strategy for prioritizing remediation?

    Answer: Address findings with the highest severity that affect internet-exposed or production resources first

    Combining severity rating with asset context (internet exposure, environment criticality) ensures that the highest-risk misconfigurations are fixed before lower-impact ones.

  6. What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?

    Answer: Secure compute workloads (VMs, containers, serverless) against runtime threats and vulnerabilities

    CWPP solutions protect cloud workloads at runtime by providing vulnerability scanning, threat detection, and behavioral monitoring for VMs, containers, and serverless functions.

  7. A security team wants to ensure that any new cloud resource deployed without required security tags is automatically flagged. Which approach implements this as a preventive control?

    Answer: Cloud provider policy-as-code that denies deployments missing required tags

    Policy-as-code (e.g., AWS SCPs, Azure Policy, GCP Organization Policies) enforces tagging requirements at deployment time, preventing non-compliant resources from being created.