exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 222 discussion

Actual exam question from CompTIA's CS0-003
Question #: 222
Topic #: 1
[All CS0-003 Questions]

When undertaking a cloud migration of multiple SaaS applications, an organization's systems administrators struggled with the complexity of extending identity and access management to cloud-based assets. Which of the following service models would have reduced the complexity of this project?

  • A. CASB
  • B. SASE
  • C. ZTNA
  • D. SWG
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Omo_Mushin
Highly Voted 9 months, 2 weeks ago
A. CASB (Cloud Access Security Broker) CASBs provide a layer of security between the organization's on-premises infrastructure and the cloud provider. They offer features like identity management, authentication, access control, and data protection, making it easier to extend identity and access management (IAM) to cloud applications. This helps in ensuring consistent security policies across on-premises and cloud environments, thus reducing complexity in managing access to SaaS applications.
upvoted 5 times
...
f90ecff
Most Recent 1 week, 5 days ago
Selected Answer: C
CASB controls what you do in cloud apps; ZTNA controls how you get to cloud apps securely.
upvoted 1 times
...
cy_analyst
7 months ago
Selected Answer: A
CASB is a service that acts as an intermediary between users and cloud service providers to enforce security policies, including identity and access management (IAM).
upvoted 3 times
...
Lilik
8 months, 3 weeks ago
A. CASB A SASE solution is generally the better option for all-around security and networking integration because it simplifies and streamlines security and network management. However, CASB is a simpler alternative that is more easily added to the organization's existing infrastructure.
upvoted 3 times
...
nap61
9 months, 3 weeks ago
Selected Answer: B
Secure Access Service Edge (SASE) combines the protection of a secure access platform with the agility of a clouddelivered security architecture. SASE offers a centralized approach to security and access, providing end-to-end protection and streamlining the process of granting secure access to all users, regardless of location. SASE is a confluence of Wide Area Networks, WANs, and Network Security Services, such as CASB, FWaaS, and Zero Trust, in a cloud-delivered service model. Lesson 3: Explaining Important System and Network Architecture Concepts | Topic 3A
upvoted 1 times
nap61
9 months, 3 weeks ago
Rectifying to A: Some of the functions of a CASB are the following: • Enable single sign-on authentication and enforce access controls and authorizations from the enterprise network to the cloud provider. Lesson 3: Explaining Important System and Network Architecture Concepts | Topic 3B
upvoted 2 times
...
...
Ree1234
11 months, 2 weeks ago
Selected Answer: A
CASB is the correct answer
upvoted 3 times
...
RiccardoBellitto
1 year ago
Selected Answer: A
The correct answer is A. CASB (Cloud Access Security Broker). Here’s why: A CASB is a software or hardware program that sits between users and a cloud service to enforce security policies around cloud-based resources. CASBs help enterprises spot unusual or malicious activity and better manage cloud access with deep visibility and granular control. It ensures organizations have comprehensive visibility of their network and protects their cloud applications against security threats. It also helps businesses reduce workloads and the complexity of their IT, which is crucial as employees use personal devices to access corporate networks from new locations.
upvoted 3 times
...
phongtran27
1 year ago
Selected Answer: C
Zero Trust Network Access is a security framework based on the principle of "never trust, always verify." It ensures that all users and devices, whether inside or outside the network perimeter, are authenticated and authorized before accessing applications and resources. ZTNA focuses on securing access to individual applications rather than the network as a whole. By implementing ZTNA, the organization's systems administrators can enforce granular access controls, authenticate users and devices, and monitor and log access to cloud-based assets during the migration process. This approach reduces the complexity of extending IAM by providing a centralized platform for managing access to multiple SaaS applications while maintaining a high level of security.
upvoted 1 times
...
Kmelaun
1 year ago
Selected Answer: B
Certmaster Topic #3A: SASE aims to simplify the complexity of managing multiple network and security services by combining networking and security functions into a single cloud-hosted service. SASE eliminates the need for dedicated hardware, which allows security teams to quickly adapt to changes while maintaining secure access to any user from any device. SASE also offers advanced features such as identity and access management, secure web gateways, and supports Zero Trust network access, all designed to protect an organization's data and applications while providing uninterrupted access to users. SASE also facilitates remote management of networks and systems. SASE helps to integrate multiple network and security services, such as network access control (NAC), web security gateways, and virtual private network (VPN) connections.
upvoted 2 times
...
Eduardoo7
1 year ago
Selected Answer: C
ZTNA always
upvoted 1 times
...
thisguyfucks
1 year ago
Selected Answer: A
CASB for cloud products
upvoted 3 times
...
section8santa
1 year, 1 month ago
Selected Answer: C
ZTNA provides secure remote access to applications based on clearly defined access control policies, no matter where the user or the application resides. It can simplify the extension of IAM by ensuring that only authenticated and authorized users and devices are able to access applications and data. ZTNA enforces the principle of least privilege, which is a key component of IAM.
upvoted 2 times
...
bettyboo
1 year, 1 month ago
Selected Answer: B
B. SASE Secure Access Service Edge Secure access service edge (SASE, pronounced “sassy”) is a network architecture design that leverages software-defined wide area networking (SD-WAN) and security functionality like cloud access security brokers (CASBs), zero trust, firewalls as a service, antimalware tools, or other capabilities to secure your network. The concept focuses on ensuring security at the endpoint and network layer, presuming that organizations are decentralized and that datacenter-focused security models are less useful in current organizations.
upvoted 1 times
...
MMK777
1 year, 1 month ago
Selected Answer: A
A. CASB (Cloud Access Security Broker) is a service model that provides visibility into and control over data and activities across cloud services. It can help enforce security policies, including identity and access management, for cloud-based applications.
upvoted 2 times
...
abee6ca
1 year, 2 months ago
Selected Answer: B
SASE offers a broader solution that encompasses the capabilities of CASB along with other essential security and networking functions. By integrating these services into a single framework, SASE reduces the complexity associated with managing multiple security solutions and network configurations for cloud migrations. It addresses not just the security of cloud applications but also the secure access and connectivity requirements of a distributed workforce accessing these applications from anywhere.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago