Chapter 4: Review Questions Flashcards

1
Q

In a cloud environment, what is elasticity?

A

Elasticity allows you to increase and decrease cloud resources as you need them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In which cloud environment would I install the software and then have to update the patches?

A

Infrastructure as a Service (IaaS) requires you to install the operating systems and patch the machines. The CSP provides bare-metal computers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What cloud model would I not be allowed to migrate to?

A

SaaS is a custom application written by a vendor and you cannot migrate to it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the major benefit of using a public cloud?

A

The major benefit of a public cloud is that there is no capital expenditure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a cloud single-tenant model?

A

A private cloud is a single-tenant setup where you own the hardware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a cloud multitenant model?

A

A public cloud is multi-tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe how a community cloud operates.

A

A community cloud is where people from the same industry, such as a group of lawyers, design and share the cost of a bespoke application and its hosting, making it cost-effective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who is responsible for the disaster recovery of hardware in a cloud environment?

A

The CSP is responsible for the hardware fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Cloud Access Security Broker (CASB)?

A

The CASB ensures that the policies between on-premises and the cloud are enforced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What model is it if you own the premises and all of the IT infrastructure resides there?

A

On-premises is where you own the building and work solely from there.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a hybrid cloud model?

A

A hybrid cloud is where a company is using a mixture of on-premises and the cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is distributive allocation?

A

Distributive allocation is where the load is spread evenly across a number of resources, ensuring no one resource is over-utilized. An example of this is using a load balancer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of model deals with identity management?

A

Security as a Service (SECaaS) provides secure identity management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Where will a diskless virtual host access its storage?

A

A diskless virtual host will get its disk space from an SAN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If you have a virtual switch that resides on a SAN, what connector will you use for a VLAN?

A

A VLAN on an SAN will use an iSCSI connector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What type of disks does a SAN use?

A

An SAN will use fast disks, such as SSDs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the machine that holds a number of VMs called?

A

A host holds a number of virtual machines – it needs fast disks, memory, and CPU cores.

18
Q

What is a guest, and what can you use as a rollback option?

A

A guest is a virtual machine, for example, a Windows 10 virtual machine. A snapshot can be used to roll back to a previous configuration.

19
Q

In a virtual environment, what is sandboxing and how does it relate to chroot jail?

A

Sandboxing is where you isolate an application for patching or testing or because it is dangerous. A chroot jail is for sandboxing in a Linux environment.

20
Q

Which is faster for data recovery: a snapshot or a backup tape?

A

A snapshot is faster at recovering than any other backup solution.

21
Q

What is a Type 1 hypervisor?

A

A Type 1 hypervisor is a bare-metal hypervisor. Some examples are Hyper-V, ESX, and Xen.

22
Q

What is a Type 2 hypervisor?

A

A Type 2 hypervisor is a hypervisor that sits on top of an operating system, for example, VirtualBox, which could be installed on a Windows 10 desktop.

23
Q

Why does HVAC produce availability for a data center?

A

HVAC keeps the servers cool by importing cold air and exporting hot air. If a server’s CPU overheats, it will cause the server to crash.

24
Q

What do you call the cloud model where people from the same industry share resources and the cost of the cloud model?

A

A community cloud is where people from the same industry share resources.

25
Q

What is an example of cloud storage for a personal user?

A

Cloud storage for personal users could be iCloud, Google Drive, Microsoft OneDrive, or Dropbox.

26
Q

Explain the functionality of fog computing.

A

Fog computing is an intermediary between the device and the cloud. It allows the data to be processed closer to the device. It reduces latency and cost.

27
Q

What is edge computing?

A

It allows data storage to be closer to the sensors rather than miles away in a data center.

28
Q

What are containers?

A

A container allows the isolation of the applications and its files and libraries so that the application is independent.

29
Q

What is infrastructure as code?

A

Infrastructure as code allows you to automate your infrastructure, for example, using PowerShell DSC.

30
Q

Describe services integration.

A

This is the combination of business and IT functions into a single business solution.

31
Q

What are cloud resource policies?

A

These are policies that state the actions and access levels someone has in relation to a particular resource.

32
Q

What is system sprawl, and what is a way to prevent it?

A

This is where a virtual machine or host has run out of resources. The best way to avoid this is to use thin provisioning.

33
Q

What is the best way to protect against VM escape?

A

VM escape is where an attacker will use a vulnerable virtual machine to attack the host of another virtual machine. The best protection against this attack is to ensure that the hypervisor and all virtual machines are fully patched.

34
Q

What is a cloud region, and how can it provide redundancy?

A

A cloud region consists of multiple physical locations called zones; data can be spread across multiple zones for redundancy.

35
Q

What is secret management, and what encryption levels protect the secret management key?

A

Secrets management uses a vault to store keys, passwords, tokens, and SSH keys used for privilege accounts. It uses RSA 2048-bit keys to protect the secret management access key.

36
Q

Explain the main difference between LRS and ZRS. Which one is the cheapest?

A

LRS replicates three copies of your data to a single physical location. This is the cheapest option. ZRS is where three copies of the data are replicated to three separate zones within your region.

37
Q

Why would a VPC use private and public subnets?

A

They would be used as a form of network segmentation.

38
Q

What type of resources would be held on a public subnet?

A

Resources that need access to the internet, for example, company web servers. A NAT gateway and an internet gateway would also be on these subnets.

39
Q

What type of resources would be held on a private subnet?

A

Resources that should not have direct internet access, such as database servers, domain controllers, and email servers.

40
Q

How would someone connect to a VPC?

A

A VPN connection using L2TP/IPSec should be used to connect to a VPC.

41
Q

Where should a default route be pointing for a device within a private subnet, and what is its purpose?

A

The default route of 0.0.0.0 should be pointing to either the NAT gateway or the internet gateway. When network traffic does not know where to go, it will be sent to the default route as a last resort.

42
Q

Why might a third-party cloud solution be better than a cloud-native solutions?

A

The third-party tools will offer more flexibility.