Courseiva

SCAZT · domain

Application And Data Security

Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) Application And Data Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

46 questions8 easy22 medium16 hard

Focused practice

Practice Application And Data Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Application And Data Security

Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Application And Data Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Application And Data Security questions (46)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO factors are critical when configuring an automated remediation workflow in Cisco Cloudlock to prevent data loss?

Hard
2

Which TWO methods can Cisco Cloudlock use to notify an administrator of a policy violation?

Medium
3

Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?

Easy
4

Which TWO actions can a user take if a file is quarantined by Cisco Cloudlock?

Hard
5

When creating a policy in Cisco Cloudlock, what is the significance of setting a 'Threshold'?

Medium
6

What is the primary role of a Cloud Access Security Broker (CASB)?

Easy
7

Which TWO settings should be verified if a Cisco Cloudlock API connector to Google Workspace is showing a 'Warning' status?

Medium
8

A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?

Hard
9

You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?

Hard
10

An administrator needs to ensure that only managed devices can access sensitive data in Box. Which Cisco solution feature enables this verification?

Hard
11

In Cisco Cloudlock, what is the purpose of an 'Incident'?

Easy
12

Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?

Medium
13

What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?

Medium
14

You are configuring a Cisco Cloudlock policy to detect sensitive PII in a Salesforce instance. Which configuration step ensures that the policy specifically triggers when sensitive data is uploaded to a public-facing object?

Medium
15

When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?

Hard
16

When setting up a DLP policy for cloud storage, which TWO elements should be defined to ensure accurate classification of sensitive data?

Hard
17

You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?

Medium
18

Which feature in Cisco Cloudlock allows you to identify if a SaaS user is logging in from an anonymizer or TOR exit node?

Easy
19

You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?

Hard
20

You have detected a compromised account in Google Workspace via Cloudlock. Which automated response action can immediately prevent further data exfiltration from this user account?

Medium
21

Which THREE actions can be performed by the Cisco Cloudlock UBA engine?

Medium
22

In Cisco Cloudlock, why would you use a 'Custom Regex' pattern in a DLP policy?

Medium
23

When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?

Hard
24

You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?

Medium
25

To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?

Medium
26

When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?

Hard
27

Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?

Medium
28

In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?

Medium
29

Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?

Medium
30

Which THREE items are included in a Cisco Cloudlock 'Incident' report?

Hard
31

What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?

Easy
32

When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?

Hard
33

When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?

Medium
34

Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?

Easy
35

In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?

Hard
36

Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?

Medium
37

When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?

Hard
38

You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?

Medium
39

If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?

Hard
40

Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?

Medium
41

Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?

Medium
42

Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?

Medium
43

You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?

Hard
44

Which term describes the unauthorized use of cloud applications by employees within an organization?

Easy
45

Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?

Medium
46

An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?

Easy

Frequently asked questions

What does the Application And Data Security domain cover on the SCAZT exam?
Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 46 Application And Data Security questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Application And Data Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-scazt CISCO-SCAZT application and data security Practice Questions