SCAZT · domain
Application And Data Security
Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) Application And Data Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Application And Data Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Application And Data Security
Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Application And Data Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Application And Data Security questions (46)
Click any question to see the full explanation, or start a practice session above.
Which TWO factors are critical when configuring an automated remediation workflow in Cisco Cloudlock to prevent data loss?
Hard2Which TWO methods can Cisco Cloudlock use to notify an administrator of a policy violation?
Medium3Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?
Easy4Which TWO actions can a user take if a file is quarantined by Cisco Cloudlock?
Hard5When creating a policy in Cisco Cloudlock, what is the significance of setting a 'Threshold'?
Medium6What is the primary role of a Cloud Access Security Broker (CASB)?
Easy7Which TWO settings should be verified if a Cisco Cloudlock API connector to Google Workspace is showing a 'Warning' status?
Medium8A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?
Hard9You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?
Hard10An administrator needs to ensure that only managed devices can access sensitive data in Box. Which Cisco solution feature enables this verification?
Hard11In Cisco Cloudlock, what is the purpose of an 'Incident'?
Easy12Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?
Medium13What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?
Medium14You are configuring a Cisco Cloudlock policy to detect sensitive PII in a Salesforce instance. Which configuration step ensures that the policy specifically triggers when sensitive data is uploaded to a public-facing object?
Medium15When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?
Hard16When setting up a DLP policy for cloud storage, which TWO elements should be defined to ensure accurate classification of sensitive data?
Hard17You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?
Medium18Which feature in Cisco Cloudlock allows you to identify if a SaaS user is logging in from an anonymizer or TOR exit node?
Easy19You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?
Hard20You have detected a compromised account in Google Workspace via Cloudlock. Which automated response action can immediately prevent further data exfiltration from this user account?
Medium21Which THREE actions can be performed by the Cisco Cloudlock UBA engine?
Medium22In Cisco Cloudlock, why would you use a 'Custom Regex' pattern in a DLP policy?
Medium23When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?
Hard24You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?
Medium25To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?
Medium26When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?
Hard27Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?
Medium28In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?
Medium29Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?
Medium30Which THREE items are included in a Cisco Cloudlock 'Incident' report?
Hard31What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?
Easy32When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?
Hard33When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?
Medium34Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?
Easy35In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?
Hard36Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?
Medium37When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?
Hard38You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?
Medium39If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?
Hard40Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?
Medium41Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?
Medium42Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?
Medium43You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?
Hard44Which term describes the unauthorized use of cloud applications by employees within an organization?
Easy45Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?
Medium46An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?
EasyOther domains
All SCAZT exam domains
Frequently asked questions
- What does the Application And Data Security domain cover on the SCAZT exam?
- Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 46 Application And Data Security questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Application And Data Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.