Home > Glossary > CompTIA Security+ Certification Exam > Cloud Access Security Broker (CASB)

📖 What is Cloud Access Security Broker (CASB)?

A Cloud Access Security Broker (CASB) is a software tool or service that sits between an organization's on-premises infrastructure and a cloud provider's infrastructure. It enforces security, compliance, and governance policies for cloud-based applications and services.

🥋 Sensei Says:

"Think of a CASB as a "firewall for the cloud" that provides visibility into "Shadow IT" and unauthorized cloud app usage."

📚 Certification: CompTIA Security+ Certification Exam (SY0-701)

🔑 What are the Key Concepts of Cloud Access Security Broker (CASB)?

  • Shadow IT Discovery: CASBs provide visibility into unauthorized cloud applications used by employees, allowing administrators to identify and block risky, unmanaged services.
  • Data Loss Prevention (DLP): They monitor data transfers to the cloud, preventing sensitive information like PII or PHI from being uploaded to unauthorized locations.
  • Compliance Enforcement: CASBs ensure cloud usage aligns with regulatory requirements by enforcing consistent security policies across multiple disparate cloud service providers.
  • Threat Protection: By analyzing user behavior and API calls, CASBs can detect anomalous activity, such as account takeovers or unusual data exfiltration patterns.
  • Deployment Architectures: CASBs can be deployed as forward proxies, reverse proxies, or via API integrations to balance real-time control with comprehensive visibility.

🎯 How does Cloud Access Security Broker (CASB) appear on the SY0-701 Exam?

You may be asked to identify the best tool for a company that needs to discover which unauthorized SaaS applications their employees are using to store corporate data.

A scenario might describe a need to prevent sensitive credit card data from being uploaded to a public cloud storage provider while maintaining a detailed audit trail.

Expect questions where you must distinguish between a CASB and a traditional firewall when the primary goal is governing data movement within cloud-native environments.

❓ Frequently Asked Questions

How does a CASB differ from a traditional network firewall?

Traditional firewalls manage traffic based on IP addresses and ports at the perimeter. CASBs operate at the application layer, focusing on cloud-specific API calls, user identities, and data content.


What is the trade-off between API-based and Proxy-based CASB deployments?

Proxy-based CASBs provide real-time blocking and control but can introduce latency. API-based CASBs offer better visibility and no latency but typically operate asynchronously, detecting issues after they occur.

Related Terms from CompTIA Security+ Certification Exam

📝 Related Study Guides

Study Guide 9 min read

How to Pass CompTIA Security+ (SY0-701) on Your First Try

To pass CompTIA Security+ SY0-701 on your first try, build a structured 6-8 week study plan covering all five domains, prioritize understanding concepts over memorization, practice with scenario-based questions daily, and consistently score 85% or higher on practice exams before scheduling your test. Hands-on lab experience is essential for performance-based questions.

Deep Dive 8 min read

Zero Trust Architecture: Security+ (SY0-701) Deep Dive

Zero Trust architecture is a security framework based on the principle "never trust, always verify." Unlike traditional perimeter security, it assumes breaches are inevitable and requires strict identity verification for every person and device attempting to access resources, regardless of whether they are inside or outside the network perimeter.

Exam Tips 8 min read

Security+ PBQs: Master Firewall ACLs & Incident Response

Security+ Performance-Based Questions (PBQs) are scenario-driven simulations requiring you to apply knowledge to real-world tasks. To master them, focus on firewall ACL rule ordering, the "implicit deny" principle, and analyzing system logs for incident response. Consistent practice with high-fidelity simulations is the most effective way to ensure exam success.

🧠

Test Your Knowledge

Think you understand Cloud Access Security Broker (CASB)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium