Courseiva
Security →mediumMultiple Select

CV0-004 Security Practice Question

A cloud administrator is configuring a CASB (Cloud Access Security Broker) for SaaS applications. Which TWO capabilities should the administrator expect from the CASB? (Choose two.)

⚠ Common exam trap

CV0-004 often tests the misconception that a CASB is a network security appliance that provides infrastructure services like DNS or patching, when it is actually a policy enforcement point for cloud usage visibility and data protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Discover and control shadow IT usage

Option A is correct because a core CASB function is discovery of shadow IT — the CASB uses API connectors, log analysis, and traffic inspection to identify unsanctioned SaaS usage and then apply control (block, coach, or allow) policies. Option C is correct because CASBs enforce data loss prevention policies on cloud traffic and data at rest, inspecting content for sensitive patterns (PII, PCI, credentials) and applying actions such as block, quarantine, or encryption via API or inline proxies. Options B, D, and E are incorrect: patch management of on-premises servers is a configuration management/endpoint tool function, local DNS resolution is provided by DNS servers (e.g., BIND, Windows DNS) rather than a CASB, and a CASB never replaces the cloud provider's infrastructure — it sits alongside SaaS/IaaS to provide visibility, compliance, threat protection, and data security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Discover and control shadow IT usage

    Why this is correct

    CASBs provide discovery of unsanctioned SaaS usage, identifying shadow IT across the organisation, then enforce granular controls such as blocking or restricting those applications. This visibility and control capability directly matches the stem's SaaS-focused CASB deployment.

  • ✗

    Manage on-premises server patches

    Why it's wrong here

    A CASB enforces policy between users and SaaS applications, covering visibility, data loss prevention and threat protection; it does not patch on-premises servers. Patch management belongs to configuration tools like Intune or WSUS, which is why server maintenance duties are mistakenly attributed here.

  • ✓

    Apply data loss prevention (DLP) policies

    Why this is correct

    CASBs inspect traffic and content flowing to and from sanctioned SaaS applications, enforcing DLP rules that block sensitive data such as personally identifiable information from leaving the organisation. This satisfies the stem's requirement for CASB capabilities protecting SaaS usage.

  • ✗

    Provide local DNS resolution

    Why it's wrong here

    A CASB brokers access to sanctioned SaaS apps, applying inline or API-based controls; it does not serve DNS for local networks. Local DNS resolution is provided by on-premises DNS servers or cloud DNS services, making this tempting when consolidating network functions under one security platform.

  • ✗

    Replace the cloud provider's infrastructure

    Why it's wrong here

    A CASB sits alongside cloud infrastructure, enforcing SaaS usage policy; it never replaces the provider's compute, storage or networking. This tempts administrators seeking unified control, but infrastructure remains the cloud provider's responsibility under the shared responsibility model, not the CASB's.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.