正解:D
A Cloud Access Security Broker (CASB) acts as a control point between cloud service users and providers to enforce the organization's security policies consistently across all cloud applications.
CRISC-aligned cloud risk guidance explains:
"CASBs provide visibility, data security, threat protection, and compliance enforcement by applying consistent security controls across all cloud services." Therefore, the main issue CASBs address is inconsistent security policy enforcement between on-premise and multiple cloud environments.
Option details:
* A and C (SSO and key management) relate to identity or encryption control tools.
* B is unrelated to CASB's purpose.
Hence, D. Inconsistently applied security policies is correct.
CRISC Reference: Domain 3 - Risk Response and Mitigation, Topic: Cloud Risk Controls.