Case B7B7A9 · Cloud · L1 Foundations
CSPM vs CWPP vs CNAPP
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CSPM checks cloud configuration against best practice: public buckets, open security groups, unencrypted disks
- CWPP protects running workloads: VMs, containers and serverless, with runtime detection and vulnerability scans
- CNAPP bundles both with identity analysis (CIEM) and code/IaC scanning into one platform
- Value comes from attack-path context: a vulnerable VM that is internet-facing with an admin role is critical
- Tooling finds issues; the hard part is routing them to owning teams and fixing root causes in IaC
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.