A company is deploying a cloud access security broker (CASB) to gain visibility into shadow IT. Which mode of operation would allow the CASB to inspect traffic without requiring proxy configuration on endpoints?
Trap 1: Reverse proxy mode
Reverse proxy sits in front of cloud apps but may require changes to DNS or routing.
Trap 2: Inline mode
Inline mode requires traffic to pass through the CASB, often needing proxy configuration.
Trap 3: Forward proxy mode
Forward proxy requires explicit configuration on end-user devices.
- A
Reverse proxy mode
Why it fails: Reverse proxy sits in front of cloud apps but may require changes to DNS or routing.
- B
Inline mode
Why it fails: Inline mode requires traffic to pass through the CASB, often needing proxy configuration.
- C
API-based mode
API-based mode connects directly to the cloud service provider's APIs, scanning stored data and activity logs for shadow IT without inline traffic interception. This satisfies the stem's constraint of gaining visibility without proxy or endpoint configuration, unlike forward or reverse proxy modes.
- D
Forward proxy mode
Why it fails: Forward proxy requires explicit configuration on end-user devices.