Courseiva

SCAZT · topic practice

Application And Data Security practice questions

Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) Application And Data Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Application And Data Security

What the exam tests

What to know about Application And Data Security

Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Application And Data Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Application And Data Security questions

20 questions · select your answer, then reveal the explanation

You are implementing Cisco Umbrella CASB to restrict file uploads to unsanctioned SaaS applications. You have configured an App Control rule, but users can still upload files to a cloud storage service. What is the most likely cause?

You are investigating a data leak in Google Drive using Cisco Cloudlock. You notice that a user shared a folder with the 'public'. How can you verify exactly who accessed this folder?

A security administrator needs to prevent users from downloading corporate files to personal devices using Cisco Cloudlock. Which policy type must be implemented to achieve this session-level control?

You are configuring a DLP policy in Cisco Cloudlock. Which setting allows the policy to ignore files that have been cryptographically signed by your organization's internal CA?

Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?

When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?

You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?

In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?

You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?

Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?

You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?

When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?

A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?

Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?

Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?

Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?

When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?

Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?

You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?

What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Application And Data Security sessions

Start a Application And Data Security only practice session

Every question in these sessions is drawn from the Application And Data Security domain — nothing else.

Related practice questions

Related SCAZT topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SCAZT exam test about Application And Data Security?
Application And Data Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Application And Data Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Application And Data Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SCAZT topics?
Use the topic links above to move to related areas, or go back to the SCAZT question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SCAZT exam covers. They are not copied from any real exam or dump site.