The correct answer is B. CASB. A Cloud Access Security Broker is specifically designed to sit between users and cloud services, monitor cloud activity, enforce access policies, and provide visibility into unauthorized cloud storage use. This directly matches the question’s requirement: showing user access to prohibited cloud storage and whether a file was downloaded to a personal device.
Exact supporting extract: the All-in-One CySA+ guide explains that a CASB “sits between each user and each cloud service,” monitors activity, enforces policies, and alerts when something is wrong. It also lists visibility as a CASB pillar, including whether users are connecting to unauthorized resources such as cloud storage not controlled by the organization.
The Sybex CySA+ Study Guide also states that CASB tools enforce security policies when cloud resources and services are used, and can help with data security, service usage and access visibility, and risk management.
The official CompTIA CySA+ CS0-003 objectives include Cloud Access Security Broker (CASB) under identity and access management / security operations architecture concepts.
Why the other options are incorrect:
A. SASE is broader architecture that may include CASB, SWG, FWaaS, and SD-WAN, but the specific tool for cloud-service visibility and policy logging is CASB.
C. EDR focuses on endpoint detection and response, not cloud storage access monitoring across cloud services.
D. SDN is software-defined networking and does not provide user-level cloud storage access logs.
Submit