Practice SCAZT Application And Data Security questions with full explanations on every answer.
Start practicing
Application And Data Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?
2When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?
3You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?
4In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?
5You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?
6Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?
7You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?
8When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?
9A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?
10Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?
11Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?
12Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?
13When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?
14Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?
15You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?
16What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?
17Which THREE items are included in a Cisco Cloudlock 'Incident' report?
18Which TWO settings should be verified if a Cisco Cloudlock API connector to Google Workspace is showing a 'Warning' status?
19Which term describes the unauthorized use of cloud applications by employees within an organization?
20When creating a policy in Cisco Cloudlock, what is the significance of setting a 'Threshold'?
21You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?
22Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?
23What is the primary role of a Cloud Access Security Broker (CASB)?
24Which TWO methods can Cisco Cloudlock use to notify an administrator of a policy violation?
25In Cisco Cloudlock, why would you use a 'Custom Regex' pattern in a DLP policy?
26When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?
27Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?
28Which TWO actions can a user take if a file is quarantined by Cisco Cloudlock?
29What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?
30You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?
31If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?
32In Cisco Cloudlock, what is the purpose of an 'Incident'?
33Which THREE actions can be performed by the Cisco Cloudlock UBA engine?
34When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?
35You are configuring a Cisco Cloudlock policy to detect sensitive PII in a Salesforce instance. Which configuration step ensures that the policy specifically triggers when sensitive data is uploaded to a public-facing object?
36When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?
37An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?
38In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?
39You have detected a compromised account in Google Workspace via Cloudlock. Which automated response action can immediately prevent further data exfiltration from this user account?
40An administrator needs to ensure that only managed devices can access sensitive data in Box. Which Cisco solution feature enables this verification?
41To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?
42Which feature in Cisco Cloudlock allows you to identify if a SaaS user is logging in from an anonymizer or TOR exit node?
43Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?
44When setting up a DLP policy for cloud storage, which TWO elements should be defined to ensure accurate classification of sensitive data?
45Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?
46Which TWO factors are critical when configuring an automated remediation workflow in Cisco Cloudlock to prevent data loss?
The Application And Data Security domain covers the key concepts tested in this area of the SCAZT exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SCAZT domains — no account required.
The Courseiva SCAZT question bank contains 46 questions in the Application And Data Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Application And Data Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included