Q24Securing the Cloud
What must be enabled to secure SaaS-based applications?
← → navigate · a answer
Community votes
Discussion · 22
5
C. Application security gateway.
To secure SaaS-based applications, an application security gateway has to be enabled. This is a security solution that sits between the user and the SaaS application, giving a secure connection and watching traffic to make sure it follows security policies.
Two-factor authentication (A) is a security measure that adds an extra layer of authentication to access a system or application, but by itself it is not enough to secure SaaS-based applications.
End-to-end encryption (B) can also be an important security measure for SaaS-based applications, but it is usually used to protect data in transit, rather than securing the SaaS application itself.
C 3
Selected Answer: C
Obviously it's C
A 3
Selected Answer: A
I would have to say A. SaaS is like Office365. An organization doesn't own the underling infrastructure to put in a ALG or MPF. HTTPS is enabled by default. So the only logical choice is MFA.
2
Ignore above, i pick A. As per question, "What must be enabled"
Some SaaS-based applications may include an application security gateway as part of their service offering, others may not. However, provider responsible for infra security and software, customer is responsible to enabled the two-factor authentication to secure user authentication to access the application. Just saying.
C 2
Selected Answer: C
https://www.strongdm.com/what-is/application-gateway#:~:text=An%20application%20gateway%20is%20a%20security%20measure%20that,services%20with%20the%20login%20credentials%20for%20the%20app.
What is an Application Gateway (App Gateway)?
An application gateway is a security measure that protects web applications. They replace traditional web applications that require the same login credentials as the data center. Instead, users access application gateways through mobile apps and cloud services with the login credentials for the app.
2
The following practices are recommended for securing SaaS environments and assets:
1. Enhanced Authentication
2. Data Encryption
...
Therefore the best answer is A
https://www.cynet.com/sspm/saas-security-the-challenge-and-7-critical-best-practices/
A 2
Selected Answer: A
The answer is definitely A.
Cannot be C because in a SaaS environment, the provider is responsible for the network infrastructure, security, and the application. The client is only responsible for the data and the people, which makes A the most sensible choice.
2
After thinking about this question again I have to agree that answer A makes more sense:
--- i vote for A
A 2
Selected Answer: A
I would go with A.
B 2
Selected Answer: B
I agree that both A & B are correct answers, but since SaaS means my data is going across the Internet I'll choose encrypting my data before securing the login with a second factor.
1
Keeping this here:
https://www.cyberark.com/what-is/app-gateway/
1
Now this is a good one lol...
Securing SaaS-based applications typically requires a combination of security measures - making options A-C all valid in the bigger picture, but of course, we must pick the BEST possible answer for this question.
I would rule out C first - Although an application security gateway offers a more complete solution than options A & B because it provides a centralized point for monitoring and controlling access to SaaS-based applications, it is also a capability that should be mainly provided by your vendor.
Now this is where it gets interesting because options A & B are BOTH valid solutions to securing SaaS applications and can be implemented at the CUSTOMER level.
If I had to choose, however, I would go with Option A.
According to Cisco DUO's website - phishing is not only a common security threat, but it is also the #1 cause of security breaches. See link below:
https://duo.com/solutions/phishing-prevention
B 1
Selected Answer: B
B is a must, so B it is
1
And A isn't?
1
My answer is a
1
My answer is a
C 1
Selected Answer: C
If that would be an option, then I would go for Cisco cloud lock, or Cisco secure access, but none of these are listed.
In this case, Cisco application security gateway seems to be the closest fit. This solution safeguards cloud applications based on this article.
https://www.cisco.com/site/us/en/products/security/cloud-application-security/index.html
1
*If that would be an option...
A 1
Selected Answer: A
Unless it specifically mentions a Cisco product, C would have been my pick, therefor I will go with A. Most SaaS products are fairly encrypted so no to B for me as well. D is irrelevant.
A 1
Selected Answer: A
Opinion - Because it is referring to SaaS rather than IaaS or Cloud Hosting, I will go with A.
C 1
Selected Answer: C
To secure SaaS-based applications, you need a way to monitor, control, and enforce security policies for apps that are outside your network perimeter. This is where an:
✅ Application Security Gateway (also known as a Cloud Access Security Broker – CASB)
1
A CASB solution is not going to stop credential theft. Since the internal security of the application itself is under cloud provider responsibility, securing the application in this context, in my opinion, relates to MFA, which is why I would stick with A