What is CASB and why is it used?

Enhance your cyber defense skills with the Security Blue Team Level 1 Test. Prepare with flashcards, multiple choice questions, and detailed explanations to ace your exam!

Multiple Choice

What is CASB and why is it used?

Explanation:
Cloud Access Security Broker (CASB) sits between users and cloud services and enforces security policies as cloud apps are used. It gives you visibility into which cloud apps are in use (including shadow IT), protects data in the cloud through controls like data loss prevention and encryption, and provides threat protection through monitoring, anomaly detection, and policy enforcement. CASB helps with compliance by auditing activity and enforcing governance across SaaS, IaaS, and PaaS. It can be deployed in API-based or proxy-based modes and works to prevent risky access or data exfiltration by applying policies at access and data levels. For example, it can block uploading a sensitive file to an unsanctioned cloud app. So the best description is that CASB provides visibility, data protection, and threat protection for the use of cloud services. It’s not a hardware firewall, not a database backup tool, and not a VPN alternative.

Cloud Access Security Broker (CASB) sits between users and cloud services and enforces security policies as cloud apps are used. It gives you visibility into which cloud apps are in use (including shadow IT), protects data in the cloud through controls like data loss prevention and encryption, and provides threat protection through monitoring, anomaly detection, and policy enforcement. CASB helps with compliance by auditing activity and enforcing governance across SaaS, IaaS, and PaaS. It can be deployed in API-based or proxy-based modes and works to prevent risky access or data exfiltration by applying policies at access and data levels. For example, it can block uploading a sensitive file to an unsanctioned cloud app.

So the best description is that CASB provides visibility, data protection, and threat protection for the use of cloud services. It’s not a hardware firewall, not a database backup tool, and not a VPN alternative.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy