A cloud security team wants to continuously monitor for misconfigured cloud resources that could expose data. Which tool category is specifically designed for this purpose?
Cloud Security Posture Management continuously scans cloud infrastructure for misconfigurations, comparing deployed resource settings against security baselines and compliance frameworks. It directly satisfies the stem's requirement for ongoing detection of exposed data risks, unlike CWPP (workload protection) or CASB (access control), which address different layers.
Why this answer
CSPM (Cloud Security Posture Management) tools detect misconfigurations like open storage buckets or overly permissive IAM roles. CWPP focuses on runtime workload protection. WAF protects web apps.
IAM manages identities, not configuration monitoring.