Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

Which of the following is a primary function of a Cloud Access Security Broker (CASB)?

⚠ Common exam trap

CAS-005 often tests the boundary between CASB and adjacent technologies — candidates confuse CASB with IAM, container security, or network monitoring because all involve 'cloud security'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce security policies between users and cloud applications

A CASB sits between users and cloud applications and enforces security policies such as data loss prevention, access control, encryption, and compliance monitoring. Its core purpose is to provide visibility and control over cloud service usage, which is exactly what Option C describes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scan container images for vulnerabilities

    Why it's wrong here

    Container image scanning is performed by registry or CI/CD scanners such as Trivy or Clair, which inspect layers for known CVEs. A CASB enforces policy between users and cloud services, covering shadow IT discovery, data loss prevention and access control, so it would be the right tool for governing sanctioned SaaS usage, not image contents.

  • ✗

    Provide IAM for cloud infrastructure

    Why it's wrong here

    IAM for cloud infrastructure is delivered by the cloud provider's own identity service, such as Microsoft Entra ID or AWS IAM, which issues and evaluates credentials. A CASB instead brokers access to cloud applications, applying session and data policies; it would be correct for controlling unsanctioned SaaS usage, not for provisioning infrastructure identities.

  • ✓

    Enforce security policies between users and cloud applications

    Why this is correct

    A CASB sits inline or via APIs between users and cloud services, enforcing policy at that boundary. This directly satisfies the stem's requirement for a primary function: it governs access and data flows to sanctioned and unsanctioned cloud applications, providing visibility and control.

  • ✗

    Monitor network traffic at the packet level

    Why it's wrong here

    Packet-level traffic inspection belongs to firewalls, IDS/IPS and network TAPs, which parse headers and payloads on the wire. A CASB operates at the API and proxy layer, inspecting cloud service activity rather than raw packets; it would be the right choice for detecting anomalous SaaS logins or data exfiltration via sanctioned apps.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.