Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

Which of the following is a benefit of using a Cloud Access Security Broker (CASB) for SaaS applications?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It gives visibility and control over Shadow IT and data protection.

CASBs provide visibility into SaaS usage and enforce security policies, such as data loss prevention (DLP) and access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It encrypts data at rest in cloud storage.

    Why it's wrong here

    CASBs provide visibility, data-loss prevention, threat protection and access control for sanctioned and unsanctioned SaaS, not encryption of stored objects. Encryption at rest is tempting because CASBs can enforce policies around it, but the actual mechanism belongs to the SaaS provider or a cloud KMS.

  • ✗

    It provides a virtual private network (VPN) for remote access.

    Why it's wrong here

    CASBs broker access to cloud services through APIs and proxies; they do not terminate VPN tunnels for remote users. The confusion is tempting because both are cloud-security access controls, yet remote-access VPN is delivered by a VPN gateway or SASE edge, not by a CASB.

  • ✗

    It replaces the need for a web application firewall.

    Why it's wrong here

    CASBs complement rather than replace a WAF; they govern SaaS usage, data and identity, while a WAF inspects HTTP traffic to protect web applications. Replacement is tempting because CASBs also inspect traffic, but the WAF's layer-7 application protection role remains distinct.

  • ✓

    It gives visibility and control over Shadow IT and data protection.

    Why this is correct

    A CASB sits between users and SaaS providers, discovering unsanctioned applications and enforcing data-loss prevention, encryption and access policies. This directly delivers the visibility and control over Shadow IT and data protection that the question asks for as the SaaS benefit.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.