3.6 Cloud Security Flashcards
1
Q
Define AZ and its relation to high-availability (2)
A
- Availability Zones - the region cloud-services are provided from, i.e. North America, South America, etc..
- Having applications, resources, located in or mirrored to different AZs ensures continued function in case of a regional disaster
2
Q
Define Resource Policies in relation to the cloud
A
Ability to control who has access to cloud resources
3
Q
Define secrets management in relation to cloud resources
A
Different cloud resources often require secrets in config files and these need to be managed in a central location with the ability to control who has access to them
4
Q
What can be implemented to provide integration and auditing capabilities for the cloud?
A
SIEM
5
Q
Cloud storage security considerations
A
- Countries have different regulations regarding storage of data that must be adhered to
- Private data stored in the cloud may be accessible to third-party employees and encryption should be considered
6
Q
Define CASB
A
Cloud-access security broker
7
Q
4 Cornerstones of CASB (VDTC)
A
- Visibility - identifies all cloud services in use
- Data security - secures data traveling to, within and stored in the cloud
- Threat protection - behavior based identification of threats
- Compliance - allows creation of policies to adhere to regulatory standards, such as HIPAA or PCI
8
Q
Define SWG
A
Next-Gen secure web gateway, provides more detail than a secure web gateway, application layer