Courseiva

CCSP Cloud Application Security Practice Question

An organization is migrating a legacy application to the cloud and plans to use a cloud access security broker (CASB). Which of the following is the PRIMARY function of a CASB in securing cloud applications?

⚠ Common exam trap

ISC2 often tests the distinction between a CASB's primary role (policy enforcement and access control) and secondary capabilities (like encryption or DLP), leading candidates to mistake a supporting feature for the core function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforcing security policies across cloud applications and controlling access

The primary function of a CASB is to enforce security policies and control access across cloud applications, acting as an intermediary between users and cloud providers. It provides visibility into cloud usage, applies data loss prevention (DLP) rules, and enforces authentication and authorization policies, which directly addresses the need to secure a legacy application migrated to the cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing vulnerability scans on cloud infrastructure

    Why it's wrong here

    Vulnerability scanning of cloud infrastructure is performed by cloud security posture tools, not a CASB, which instead enforces policy on sanctioned and unsanctioned SaaS usage, data loss and access. Scanning is a real cloud security control, which is why it appears plausible as a CASB function.

  • ✗

    Encrypting data at rest in cloud storage

    Why it's wrong here

    A CASB brokers access between users and cloud services, enforcing policy, visibility and data-loss controls; it does not encrypt stored objects. Encryption at rest is delivered by the cloud provider's storage service or customer-managed keys, so this describes a storage-layer control rather than the CASB's inline mediation role.

  • ✗

    Protecting against distributed denial-of-service (DDoS) attacks

    Why it's wrong here

    DDoS mitigation is handled by edge scrubbing services and cloud provider network protections, not by a CASB. A CASB sits between users and sanctioned or unsanctioned SaaS to enforce access and data policies, so this option names a network-perimeter defence that operates at a different layer entirely.

  • ✓

    Enforcing security policies across cloud applications and controlling access

    Why this is correct

    A CASB sits inline between users and cloud services, applying policy enforcement and access control as its core function. This directly addresses the migration scenario's need to govern sanctioned and unsanctioned cloud application usage, covering visibility, data loss prevention, threat protection and compliance enforcement.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.