ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization has migrated its email and file collaboration workloads to Microsoft 365. Employees often connect to the service directly from home or on personal mobile devices, so much of the traffic never traverses the corporate network where your existing inline network-based DLP appliances sit. Management wants a data loss prevention capability that can discover and control sensitive information stored in Exchange Online and OneDrive-even when users access the service off-network-without requiring software installation on every endpoint. Which approach best satisfies these requirements?
Deploy endpoint DLP agents on all corporate laptops and configure them to monitor file operations and uploads.
Require all remote users to connect through the corporate VPN so existing on-premises network DLP appliances can inspect traffic.
Rely on Microsoft 365's default encryption for data at rest and in transit to mitigate data-loss risks without additional tooling.
Implement an API-based CASB that connects to the Microsoft 365 tenant and enforces DLP policies within the cloud service.
An API-based cloud access security broker (CASB) that integrates directly with the SaaS provider receives delegated administrative access through published APIs. This allows it to scan data already stored in the cloud (data at rest) and to apply DLP policies to new content and sharing events (data in motion) regardless of the user's location or device, because inspection occurs within the provider's environment. Endpoint DLP agents can be effective but must be installed and managed on every managed device and provide no coverage for unmanaged or mobile endpoints. Forcing all remote users through a VPN re-introduces backhaul latency and still fails to address data that is already resident in the SaaS storage. Relying solely on the provider's native encryption protects confidentiality in transit and at rest but does not detect or block inappropriate sharing or exfiltration. Therefore, the API-based CASB/DLP integration is the most comprehensive and manageable solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an API-based CASB?
Open an interactive chat with Bash
How does an API-based CASB differ from endpoint DLP agents?
Open an interactive chat with Bash
Why is forcing users to use a VPN not ideal for cloud DLP purposes?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .