CCSP Cloud Application Security Practice Question
An organization is migrating a legacy application to the cloud and plans to use a cloud access security broker (CASB). Which of the following is the PRIMARY function of a CASB in securing cloud applications?
⚠ Common exam trap
ISC2 often tests the distinction between a CASB's primary role (policy enforcement and access control) and secondary capabilities (like encryption or DLP), leading candidates to mistake a supporting feature for the core function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforcing security policies across cloud applications and controlling access
The primary function of a CASB is to enforce security policies and control access across cloud applications, acting as an intermediary between users and cloud providers. It provides visibility into cloud usage, applies data loss prevention (DLP) rules, and enforces authentication and authorization policies, which directly addresses the need to secure a legacy application migrated to the cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing vulnerability scans on cloud infrastructure
Why it's wrong here
Vulnerability scanning of cloud infrastructure is performed by cloud security posture tools, not a CASB, which instead enforces policy on sanctioned and unsanctioned SaaS usage, data loss and access. Scanning is a real cloud security control, which is why it appears plausible as a CASB function.
- ✗
Encrypting data at rest in cloud storage
Why it's wrong here
A CASB brokers access between users and cloud services, enforcing policy, visibility and data-loss controls; it does not encrypt stored objects. Encryption at rest is delivered by the cloud provider's storage service or customer-managed keys, so this describes a storage-layer control rather than the CASB's inline mediation role.
- ✗
Protecting against distributed denial-of-service (DDoS) attacks
Why it's wrong here
DDoS mitigation is handled by edge scrubbing services and cloud provider network protections, not by a CASB. A CASB sits between users and sanctioned or unsanctioned SaaS to enforce access and data policies, so this option names a network-perimeter defence that operates at a different layer entirely.
- ✓
Enforcing security policies across cloud applications and controlling access
Why this is correct
A CASB sits inline between users and cloud services, applying policy enforcement and access control as its core function. This directly addresses the migration scenario's need to govern sanctioned and unsanctioned cloud application usage, covering visibility, data loss prevention, threat protection and compliance enforcement.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.