Enforcing Role-Based Security Policies for SaaS Applications

Answer Correct answer: A — Implement a Cloud Access Security Broker (CASB) to enforce role-based security policies for SaaS applications.

A security analyst is working with a vendor to get a new SaaS application deployed to an enterprise. The analyst wants to ensure role-based security policies are correctly applied as users access the application. Which of the following is most likely to solve the issue?

  1. CASB Correct Answer
  2. AUP
  3. NG-SWG
  4. VPC endpoint

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of Cloud Access Security Broker (CASB) capabilities in managing SaaS application security and user access controls.

CASB is the primary solution for enforcing role-based security policies in SaaS environments. This page explains why CASB is the correct choice over other network and policy tools.

Confusing CASB with Next-Generation Secure Web Gateways (NG-SWG), which focus more on traffic filtering than granular SaaS identity management.

Community Discussion (5 comments)

Benrosan 👍 17 Selected: A
Score another one for CASB.
NetworkTester1235 👍 10
When in doubt, its CASB
Phlorem 👍 3
The love I got for CASB is real
salah112 👍 4 Selected: A
A. CASB CASB stands for Cloud Access Security Broker, and it is a solution designed to provide security policies and controls for organizations as they migrate to cloud-based services. CASBs are particularly effective in enforcing security policies for Software as a Service (SaaS) applications.
Hs1208 👍 1 Selected: A
Cloud Access Security Broker (CASB)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Cloud Access Security Broker (CASB) acts as an intermediary between cloud service users and providers, enabling organizations to enforce security policies. It provides visibility, compliance assurance, and threat protection specifically tailored for SaaS applications like Office 365 or Salesforce. By integrating with identity providers, a CASB can enforce role-based access control (RBAC) and ensure that only authorized users access specific resources within the SaaS environment.

Why the Other Options Are Wrong

An Acceptable Use Policy (AUP) is a legal document outlining rules for employees, not a technical enforcement mechanism. A Next-Generation Secure Web Gateway (NG-SWG) focuses on web traffic inspection and filtering but lacks the deep integration with SaaS APIs needed for granular role-based policy enforcement. VPC endpoints are used to connect Virtual Private Clouds to AWS services privately, which is irrelevant for general enterprise SaaS application security.

Community Comment Notes

The community overwhelmingly agrees on CASB, with comments highlighting its specific utility for SaaS security. One user noted, "Score another one for CASB," reflecting the strong consensus. Another emphasized, "When in doubt, its CASB," indicating it is the go-to answer for cloud access security questions.

Exam Strategy

For any question involving SaaS security, visibility, or policy enforcement, prioritize CASB as the answer. Distinguish it from NG-SWG by remembering that CASB integrates directly with SaaS APIs for identity and data control.

Frequently Asked Questions

Why not use an NG-SWG for SaaS security?

NG-SWG filters web traffic but doesn't integrate deeply with SaaS APIs for granular role-based access control.

Is a CASB required for all cloud services?

No, it's primarily for SaaS and IaaS where you need visibility and policy enforcement beyond basic network controls.

Related Analysis

← Back to SY0-601 Study Guide