7 - Cloud Computing Security Challenges Flashcards

1
Q

Elastic Resources

A

Scale up/down to meet demand

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Measured service

A

Pay per use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Resource Pooling

A

Resourcees pooled to multiple consumers using a multi-tenant model.

Different physical and virtual resources dynamically assigned/reassigned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

On-demand self service

A

Customer can provision their own computing capabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

High Availability/Broad network access

A

Available over the network and accessed through standard mechanisms that promoto use by heterogeneous platforms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Private cloud

A

Single organisation (comprising multiple consumers)

Owned/managed/operated by the organisation, a 3rd party or mix. On or off prem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Community Clooud

A

For use by a community of consumers from orgs that have shared interest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Public Cloud

A

Open use by general public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Hybrid Cloud

A

Composition of two/more other cloud types that are unique entities but bound by standardised/proprietary tech that enables data/app portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IaaS

A

Infrastructure as a service

Provision fundamental computing resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PaaS

A

Deploy customer apps using languages, libraries etc supported by the provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SaaS

A

Software as a service

Use provider’s own apps on a cloud service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Advantages of Cloud
LIHCD

A
  • Lower costs (software/computing)
  • Improved performance and availability
  • High storage capacity
  • Continuous updates
  • Data sharing and group work(?)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Key Cloud Issues

A
  • Client has no control of infrastructure (black box)
  • Who are we sharing with?
  • Requires internet conneciton
  • Limited flexibility
  • Different protocols/APIs
  • Data security/privacy (lose control, multi-tenancy, data leakage)
  • Does the provider comply with the same regulations/policy?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cloud Security Solutions

A
  • Isolation/protection of VMs
  • APIs for reporting/auditing/alerts
  • Docker-based services
  • Data encryptions
  • Security policies
  • Mapping of security controls for internally hosted apps to the cloud infra
  • Audit and compliance
  • Multi factor auth for example,
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Docker

A

Platform for running apps inside containers.

Allows developers to package apps and dependencies into portable isolated unites

17
Q

Docker Issues

A
  • Misconfigurations, vulnerable images, inadequate access controls
  • Shared kernal vulnerabilities or compromised host systems can impact security of Docker containers
18
Q

Security as a service

A

Extra layer of security

Cloud IDS
Anti DDOS systems
Physical security
Backup, recovery and archive
Data residency/location

19
Q

CSA

A

Cloud Security Alliance