ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A multinational enterprise stores customer data in a cloud-based CRM delivered as SaaS. Security testing shows that users can export the entire customer table to local drives, violating several data-protection laws. The company wants to block such bulk downloads while making no code changes to the SaaS application and without installing agents on every endpoint. Which control best meets these requirements?
Implement a CASB operating in API mode to apply DLP rules that prevent bulk exports from the CRM tenant.
Enable database-level Transparent Data Encryption with customer-managed keys for the SaaS environment.
Require users to connect through an always-on IPSec VPN before accessing the CRM portal.
Migrate identity federation from OAuth2 to SAML 2.0 with signed assertions.
A cloud access security broker (CASB) deployed in API mode can connect directly to the SaaS tenant and apply content-aware data loss prevention (DLP) policies. Because enforcement happens through the provider's API, no endpoint agents or application code changes are required. Transparent Data Encryption protects data at rest but does not stop exports. An always-on IPSec VPN only secures the transport path and does not inspect or block sanctioned downloads. Switching to SAML 2.0 federation strengthens authentication but provides no DLP capability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a CASB and how does it work in API mode?
Open an interactive chat with Bash
Why wouldn't Transparent Data Encryption (TDE) prevent bulk exports in this scenario?
Open an interactive chat with Bash
What are the limitations of an always-on IPSec VPN in securing SaaS applications?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .