An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?
Runtime protection continuously monitors executing workloads for malicious behaviour such as process injection or fileless attacks, then blocks or alerts in real time. This satisfies the hybrid cloud constraint because on-premises and cloud workloads share the same runtime threat surface, which static scanning alone cannot address.
Why this answer
Runtime protection (D) is essential because a CWPP must continuously monitor executing processes, detect malicious behavior such as fileless attacks or cryptomining, and block threats in real time across VMs, containers, and serverless workloads in hybrid environments. Vulnerability management (E) is equally essential since CWPPs must scan workloads for missing patches, misconfigurations, and known CVEs (e.g., via agents or agentless snapshots) to prioritize remediation before exploitation. Options A, B, and C, while valuable security disciplines, are typically delivered by SIEM, IAM, and DLP platforms respectively, and are not the defining workload-protection capabilities of a CWPP.
Exam trap
CAS-005 often tests whether candidates can distinguish CWPP's workload-centric capabilities (runtime protection, vulnerability management) from adjacent enterprise security domains (SIEM, IAM, DLP) that are frequently bundled in vendor marketing but are not core CWPP functions.