Question

Difficulty: MediumCloud Architecture and Deployment Models

An enterprise security architect is designing a defense-in-depth framework across a multi-cloud environment. Match each cloud security technology on the left with its primary operational function on the right.

  • Cloud Access Security Broker (CASB)Enforces security policies, access controls, and data loss prevention (DLP) inline or via API between consumers and cloud application providers.
  • Cloud Security Posture Management (CSPM)Continuously audits cloud control planes and resource configurations against security benchmarks to detect drift and compliance violations.
  • Cloud Workload Protection Platform (CWPP)Provides specialized runtime threat detection, vulnerability auditing, and hardening controls directly inside virtual machines, containers, and serverless tasks.
  • Secure Access Service Edge (SASE)Converges Software-Defined WAN (SD-WAN) networking capabilities with cloud-delivered security services such as Zero Trust Network Access (ZTNA) and Secure Web Gateways.

Answer

Cloud Access Security Broker (CASB) matches with policy and DLP enforcement between users and cloud applications; Cloud Security Posture Management (CSPM) matches with continuous audit of cloud resource configurations and compliance drift; Cloud Workload Protection Platform (CWPP) matches with runtime threat detection and vulnerability management for workloads (VMs, containers); Secure Access Service Edge (SASE) matches with the convergence of SD-WAN networking and cloud-delivered security controls.
Each cloud security solution targets a distinct architectural operational boundary: CASB protects application-level usage and data flows; CSPM monitors infrastructure control plane compliance and configuration hygiene; CWPP secures individual compute workload runtimes; and SASE converges network transport infrastructure with edge-delivered security controls.

Step-by-Step Solution

1
Identify the primary scope of Cloud Access Security Broker (CASB).
CASB secures user interaction with cloud applications (SaaS/PaaS) by enforcing governance, authentication, and Data Loss Prevention (DLP).
CASB acts as an intermediary policy enforcement point between endpoints and cloud service providers.
2
Identify the primary scope of Cloud Security Posture Management (CSPM).
CSPM audits cloud management planes for misconfigurations and regulatory compliance drift.
CSPM continuously inspects environment settings against baseline security standards.
3
Identify the primary scope of Cloud Workload Protection Platform (CWPP).
CWPP secures compute resources (VMs, containers, serverless instances) at runtime.
CWPP provides workload-centric security features such as process monitoring and container image scanning.
4
Identify the primary scope of Secure Access Service Edge (SASE).
SASE combines wide-area network routing (SD-WAN) with cloud-delivered security services like ZTNA and SWG.
SASE integrates network routing with cloud-native security enforcement at the edge.

Key Concept

Cloud Security Architecture and Monitoring Solutions
Rate this question