SCAZT Cloud Security Architecture Practice Question
When evaluating cloud security reference architectures, what is the primary purpose of a 'Cloud Access Security Broker' (CASB)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To enforce security policies and provide visibility into SaaS and cloud applications.
A CASB sits between cloud service consumers and providers to enforce security policies, ensuring visibility, compliance, and threat protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To act as a secondary DNS server for the enterprise.
Why it's wrong here
DNS is not a CASB function.
- ✗
To manage physical access to cloud data centers.
Why it's wrong here
Physical access is the responsibility of the cloud provider.
- ✓
To enforce security policies and provide visibility into SaaS and cloud applications.
Why this is correct
This is the core function of a CASB.
- ✗
To perform load balancing for cloud traffic.
Why it's wrong here
Load balancing is an infrastructure service, not a CASB function.
About these practice questions
Courseiva writes every SCAZT question from scratch — 316 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Cisco exam blueprint
This SCAZT practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCAZT exam.