Home > Glossary > CompTIA Network+ Certification Exam > Cloud Access Security Broker (CASB)

📖 What is Cloud Access Security Broker (CASB)?

Cloud Access Security Broker (CASB) is a software tool or service that sits between cloud service consumers and cloud service providers. It enforces security, compliance, and governance policies for data moving to and from the cloud.

🥋 Sensei Says:

"Focus on 'shadow IT'—CASBs are specifically designed to help organizations discover and control unauthorized cloud application usage."

📚 Certification: CompTIA Network+ Certification Exam (N10-009)

🔑 What are the Key Concepts of Cloud Access Security Broker (CASB)?

  • Shadow IT Discovery: Identifying unauthorized cloud applications used by employees to prevent data leaks and ensure compliance with corporate security policies.
  • Data Loss Prevention (DLP): Monitoring and controlling data transfers to the cloud to ensure sensitive information like PII is not uploaded insecurely.
  • Policy Enforcement: Applying consistent security rules, such as multi-factor authentication or access restrictions, across multiple different cloud service providers.
  • Visibility and Governance: Providing a centralized dashboard to audit cloud usage, monitor user behavior, and ensure regulatory compliance across hybrid environments.
  • Deployment Modes: Implementing via API-based integration for data-at-rest or as a forward/reverse proxy for real-time traffic monitoring and control.

🎯 How does Cloud Access Security Broker (CASB) appear on the N10-009 Exam?

A scenario might describe a company discovering that employees are using unauthorized personal storage accounts to share corporate files; you would identify a CASB as the solution to discover and block this shadow IT.

You may be asked to select the best tool for enforcing a single security policy across multiple third-party SaaS applications to ensure consistent data governance and compliance.

Expect questions where you must distinguish between a traditional firewall and a CASB when the primary goal is monitoring API-level interactions with a cloud provider.

❓ Frequently Asked Questions

How does a CASB differ from a Next-Generation Firewall (NGFW)?

While an NGFW controls traffic at the network layer based on ports and protocols, a CASB operates at the application layer, providing deeper visibility into specific cloud app actions and data movements.


What is the relationship between CASB and Shadow IT?

CASBs are the primary tool for combating shadow IT by analyzing network logs to identify which unauthorized cloud services are being accessed by users without IT's knowledge.


Does a CASB only work with SaaS applications?

No, while heavily used for SaaS, CASBs also provide security and governance for PaaS and IaaS environments, ensuring that cloud infrastructure configurations meet security standards.

Related Terms from CompTIA Network+ Certification Exam

📝 Related Study Guides

Exam Tips 8 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ N10-009 exam contains up to 90 questions in 90 minutes, requiring 720 out of 900 to pass. It covers five domains: Networking Fundamentals (23%), Network Implementation (20%), Network Operations (18%), Network Security (19%), and Network Troubleshooting (20%). Expect multiple choice, multiple select, and performance-based questions testing hands-on networking skills.

Exam Tips 10 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. To pass, you must master five core domains: Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting, focusing heavily on real-world scenario application.

Exam Tips 10 min read

CompTIA Network+ (N10-009): What to Expect on the Exam

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. You must master five core domains—Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting—to achieve a passing score of 720 on a scale of 100-900.

🧠

Test Your Knowledge

Think you understand Cloud Access Security Broker (CASB)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium