exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 390 discussion

Actual exam question from CompTIA's SY0-501
Question #: 390
Topic #: 1
[All SY0-501 Questions]

An organization recently moved its custom web applications to the cloud, and it is obtaining managed services of the back-end environment as part of its subscription. Which of the following types of services is this company now using?

  • A. SaaS
  • B. CASB
  • C. IaaS
  • D. PaaS
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Security Broker (CASB) gives you both visibility into your entire cloud stack and the security automation tool your IT team needs.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jenkins3mol
Highly Voted 5 years, 8 months ago
Paas should be the answer... security broker can not provide the whole suite...
upvoted 17 times
who__cares123456789___
4 years, 4 months ago
All I know is this is C or D...back end could mean the platform (PaaS)provided but this is usually for DevOps. This speaks of current apps already developed and in use??? so I will go with (IaaS) as Lead2Pass, a paid site that costs 100$ and boasts 96% accuracy has IaaS as their answer.....if I remember correctly.
upvoted 2 times
...
...
MelvinJohn
Highly Voted 5 years, 3 months ago
Correct Answer: A The question doesn’t mention security so not CASB – and the question indicates that the web applications are not in production, not development so not PaaS – and the question doesn’t mention a need for scalability to run on demand so not IaaS. That leaves SaaS. Software as a Service (SaaS) simply involves hosting software in the cloud (like Salesforce.com) so it doesn't take up on-premises resources. Infrastructure as a Service (IaaS) provides virtual machines or storage from a provider on demand with elastic scalability. PaaS is a set of services aimed at developers that helps them develop and test apps without having to worry about the underlying infrastructure. A cloud access security broker (CASB) provides visibility, data security with Data Loss Prevention (DLP), and threat protection so you can safely use cloud apps.
upvoted 12 times
FNavarro
4 years, 3 months ago
That is wildly incorrect. SaaS is software as a services (like Office 365)--you're using someone else's software .... as a service.
upvoted 3 times
...
...
fonka
Most Recent 3 years, 11 months ago
The key word is subscription meaning pay as you go (demand) or user pay for the service like Microsoft word or excell service require a subscription for a year or months meaning this is soft ware as a service (Saas) The answer is SAAS
upvoted 1 times
...
DraconianMonk
4 years, 1 month ago
Custom WEB Apps require a WAF, The WAF was removed and replaces by cloud services. The loss of WAF security is offset by CASB.
upvoted 1 times
...
DraconianMonk
4 years, 1 month ago
Custom WEB Apps require a WAF, The WAF was removed and replaces by cloud services. The loss of WAF security is offset by CASB.
upvoted 1 times
...
DraconianMonk
4 years, 1 month ago
The term CASB was coined by Gartner in 2012, and though there are multiple Gartner definitions of CASB existing on public forums, one of the simplest one goes as “products and services that address the security gaps in an organization’s cloud usage”. The cloud is replete with security controls such as Web Application Firewalls (WAF), Identity and Access Management (IAM), Secure Web Gateways (SWG), which address very specific cloud security use cases and can’t match the depth of security functions offered by a CASB. A CASB brings the same impact to the cloud security world that NGFW brought to the network security world.
upvoted 1 times
...
jbnkb
4 years, 6 months ago
Okay I don't claim to know Security all that well but I do work in the cloud and CASB is not the right answer for this one. There is no mention that they are getting managed services for Security. It has to be PaaS as they are getting managed services for the backend of their website. Meaning the platform is managed by the provider the company only has to manage the web application code. If it was code as well then it would have been SaaS.
upvoted 3 times
...
BillyKidd
4 years, 6 months ago
I don't get why the answer is B. They're not talking about a middle layer between the cloud and the enterprise organization, nor is the word "security" even mentioned. Answer SHOULD be D.
upvoted 2 times
...
DookyBoots
4 years, 8 months ago
Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions in order to improve operations and cut expenses. It is an alternative to the break/fix or on-demand outsourcing model where the service provider performs on-demand services and bills the customer only for the work done. Under this subscription model, the client or customer is the entity that owns or has direct oversight of the organization or system being managed whereas the Managed Services Provider is the service provider delivering the managed services. The client and the MSP are bound by a contractual, service-level agreement that states the performance and quality metrics of their relationship.Wikipedia A CASB acts as a gatekeeper between data on the cloud and the users who access it. CASBs also assist with data loss prevention. Whether you hire a CASB or not, you should still encrypt all communications your company and your cloud service provider.
upvoted 1 times
DookyBoots
4 years, 8 months ago
A CASB is a security policy enforcement solution that may be installed on-premise or may be cloud-based. The goal of the CASB is to enforce proper security measures an ensure that they are implemented between a cloud solution and a customer organization.
upvoted 1 times
...
...
Abdul2107
4 years, 9 months ago
It’s PaaS. You have a web app that you need to maintain, but you don’t care about the infrastructure.
upvoted 2 times
...
kentasmith
4 years, 9 months ago
A cloud access security broker (CASB) is a software tool or service that sits between an organization's on-premises infrastructure and a cloud provider's infrastructure. PaaS provides the framework needed to build, test, deploy, manage, and update software products. It utilizes the same basic infrastructure as IaaS, but it also includes the operating systems, middleware, development tools, and database management systems needed to create software applications. This is a custom web app and not Office365 which would fall under SAAS. There is no mention of the cloud provider providing hardware. I could be wrong.
upvoted 1 times
...
Kudojikuto
4 years, 10 months ago
D: PaaS
upvoted 4 times
...
Apple6900
4 years, 10 months ago
Why not IaaS? The organization is moving its custom web applications, so it is not clear if SaaS is what they need. If the cloud is providing middleware, like SQL or similar, runtime environment, etc., then it could be PaaS.
upvoted 2 times
...
Ales
5 years, 6 months ago
B. CASB A cloud access security broker (CASB) is a software tool or service that sits between an organization's on-premises infrastructure and a cloud provider's infrastructure. A CASB acts as a gatekeeper, allowing the organization to extend the reach of their security policies beyond their own infrastructure. CASBs use auto-discovery to identify cloud applications in use and identify high-risk applications, high-risk users and other key risk factors. Cloud access brokers may enforce a number of different security access controls, including encryption and device profiling. They may also provide other services such as credential mapping when single sign-on is not available. CASBs typically offer the following: Firewalls to identify malware and prevent it from entering the enterprise network. Authentication to checks users' credentials and ensure they only access appropriate company resources. Web application firewalls (WAFs) to thwart malware designed to breach security at the application level, rather than at the network level. Data loss prevention (DLP) to ensure that users cannot transmit sensitive information outside of the corporation.
upvoted 6 times
NeGaTiVeOnE
5 years, 3 months ago
The question never states someone is in the middle providing services. The answer has to be PaaS. PaaS means back-end devices are being maintained by the cloud provider - which is what the question seems to be indicating.
upvoted 6 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...