exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 89 discussion

Actual exam question from CompTIA's CS0-002
Question #: 89
Topic #: 1
[All CS0-002 Questions]

A company's Chief Information Officer wants to use a CASB solution to ensure policies are being met during cloud access. Due to the nature of the company's business and risk appetite, the management team elected to not store financial information in the cloud. A security analyst needs to recommend a solution to mitigate the threat of financial data leakage into the cloud. Which of the following should the analyst recommend?

  • A. Utilize the CASB to enforce DLP data-at-rest protection for financial information that is stored on premises.
  • B. Do not utilize the CASB solution for this purpose, but add DLP on premises for data in motion.
  • C. Utilize the CASB to enforce DLP data-in-motion protection for financial information moving to the cloud.
  • D. Do not utilize the CASB solution for this purpose, but add DLP on premises for data at rest.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
naleenh
1 year, 9 months ago
Selected Answer: C
C: the best approach is to utilize the CASB to enforce DLP (Data Loss Prevention) data-in-motion protection for financial information moving to the cloud.
upvoted 1 times
...
kiduuu
2 years ago
Selected Answer: C
The company has decided not to store financial information in the cloud, so the risk of financial data leakage into the cloud is specifically related to data in motion
upvoted 1 times
...
OnA_Mule
2 years, 1 month ago
Selected Answer: C
It's data in motion, so A+D are obviously out. I initially thought that it would be B, since the data doesn't reside in the cloud, but after doing more research, it appears that CASB can also scan data in transit to identify sensitive information and apply policy controls to prevent it from being stored in unapproved cloud services or locations.
upvoted 2 times
...
[Removed]
2 years, 1 month ago
Selected Answer: C
Certainly C. We are still using a DLP, but ensuring that data-in-motion protection is being reinforced during any transactions between on-site and cloud.
upvoted 1 times
...
2Fish
2 years, 1 month ago
Selected Answer: C
C. I really wanted to say B, but CASB can be used to protect Data in motion from on-prem to cloud. CASB can also apply DLP policies to encrypted traffic, which is important as more and more cloud applications are using encrypted traffic by default.
upvoted 1 times
...
jleonard_ddc
2 years, 2 months ago
Selected Answer: B
We need to protect data in motion (“leakage into the cloud”). This eliminates options A and D. The company does not store data in the cloud, so we need to use DLP to ensure it never reaches there. WRONG ANSWERS • A – The company is looking to protect data from moving to the cloud, not data at rest. Furthermore, data is not in the cloud at all so a CASB is not appropriate. • C – CASBs can leverage DLP for protection, but the company is not storing data in the cloud so it’s not likely a CASB would help. • D – DLP would help their cause since data is not in the cloud, but they want to stop data in motion (not at rest)
upvoted 2 times
JoInn
2 years, 2 months ago
I think CASB would help in this case, by blocking the data-in-motion from trying to enter the cloud. I think C is correct.
upvoted 2 times
...
...
knister
2 years, 3 months ago
Selected Answer: B
I am going for B here. The reason is that CASB is useless since you have this data on premises. The DLP solution will avoid the data to be uploaded to the cloud. CASB will not help avoid this.
upvoted 2 times
OnA_Mule
2 years, 1 month ago
Actually, a CASB DLP solution can also scan data in transit to identify sensitive information and apply policy controls preventing it from being stored in the cloud. So CASB does in fact help here too.
upvoted 1 times
...
...
prntscrn23
2 years, 4 months ago
Selected Answer: C
Voting for C as the concern is data leakage while data in motion mot at rest. Also, the conpany does not like to store data in the cloud.
upvoted 1 times
...
Cizzla7049
2 years, 5 months ago
Selected Answer: B
Should be B. DLP will monitor and stop data in motion if there is financial info going to the cloud.
upvoted 1 times
...
TheStudiousPeepz
2 years, 6 months ago
Selected Answer: C
You need CASB and the problem is only concerned with data in motion. Hence C
upvoted 1 times
...
SolventCourseisSCAM
2 years, 6 months ago
Selected Answer: C
Answer C is correct. Financial info is not stored in the cloud, but their concern the financial infos leakage into the cloud. This is not the data at rest, but data in motion. To mitigate financial infos leakage into cloud, company needs to utilize CASB to enforce/implement DLP for data-in-motion. So, the answer C is right.
upvoted 4 times
...
david124
2 years, 6 months ago
Selected Answer: A
A it is
upvoted 1 times
gingham_gansta
2 years, 6 months ago
You need to provide some more justifications for your answers - you're often contrary to the consensus and *wrong*.
upvoted 1 times
david124
2 years, 5 months ago
My Apologies, i answered this for the wrong question
upvoted 1 times
...
...
...
buchhe
2 years, 6 months ago
A! is the answer in my understanding of the question. The question is not for the data in motion but about storing company's sensitive data in the cloud and mitigating leakage.
upvoted 1 times
forklord72
2 years, 6 months ago
But the question is concerning data leaking into the cloud, meaning the financial data not being stored there at all.
upvoted 2 times
...
...
forklord72
2 years, 6 months ago
Selected Answer: D
My thought process: I don’t think it can be A or C since this issue concerns data in motion. CASB does implement DLP but I have no idea if that concerns data moving from the cloud only or from company premises as well. I think D is the safest answer here.
upvoted 2 times
forklord72
2 years, 6 months ago
Correction: Can’t be A or D. Meant to vote for B.
upvoted 1 times
...
...
rv438360
2 years, 7 months ago
answer should be A
upvoted 4 times
...
TheSkyMan
2 years, 8 months ago
Answer looks right. "CASB solutions generally offer their own DLP policy engine, allowing you to configure DLP policies in a CASB and apply them to cloud services." https://www.mcafee.com/blogs/enterprise/cloud-security/how-a-casb-integrates-with-an-on-premises-dlp-solution/
upvoted 4 times
MacherNewSrCyberSecAnal
2 years, 1 month ago
The answer to the question is base64 "RlVDSyBGVUNLIEZVQ0sgRlVDSyBGVUNLIEZVQ0sgRlVDSyBGVUNLIEZVQ0sgRlVDSyA="
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago