Chapter 5 - Security In The Cloud Flashcards

1
Q

What are csp and cc responsibilities in the different service models

A

CC: Security governance, Risk and compliance; data security; application security (IaaS & PaaS); Platform Security (IaaS)

CSP: Physical Security; Infrastructure Security (PaaS & SaaS), Platform Security (SaaS)

Shares: application security (SaaS), platform security (PaaS), Infrastructure Security (IaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are common risks in public cloud?

A

Vendor lock in
Vendor lock out
Multitenant Environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are common risks in IaaS

A

Personnel threats
External threats
Lack of specific skillset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are common risks in PaaS

A

Interoperability issues e.g. software and OS which is maintained by CSP

Persistence backdoors used by developers for test purposes

Virtualization

Resource sharing: information bleed and side channel attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are common risks in SaaS

A

Proprietary formats

Virtualization

Web application security (API)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are common risks for virtualization?

A

Attacks on hypervisors : preferred are type 2 attacks as OS, Hypervisor and Host is affected. OS additionalem include more vulnerabilities because of complexity

Guest escape : user escapes from vom and accesses other VMs (host escape is same for escaping the complete host)

Information bleed: processed information can be detected

Data Seizure: legal action and seizing of host machine where your vm is located

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which types of hypervisors exist?

A

Type 1 and 2

1: baremetal or hardware hypervisor that resides on host
2: software hypervisor that resides on OS which resides in host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are threats by private cloud

A
Malware
Internal threats
External threats
Man in the middle attacks
Social engineering
Theft or loss of devices
Regulatory violations
Natural disasters
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are threats in the community cloud

A

All of private cloud threats plus…

Loss of policy because of distributed ownership

Lots of physical control

Lack of audit access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Threats in public cloud

A

All of community and private plus…

Rogue administrator: like internal threats but with enhanced access

Escalation of privilege

Contractual failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are cloud specific BIa concerns?

A

New dependencies e.g. upstream and downstream

Regulatory failover: privet can’t meet regulatory requirements

Data breaches or inadvertent disclosure: liability cannot be transferred

Vendor lock in and lock out: should be per of cost benefit analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

BR and BC responsibilities customer and provider

A

Private architecture and cloud service as backup

Cloud operations and cloud provider as backup

Cloud operations and third party cloud backup provider: hard to align because of two negotiation partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DR and BC declaration

A

There should be a Preußen or office responsible for declaring a disaster. There shortly be a defined process and also a process for back to normal declaration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Testing in DR and BC

A

Backups should be tested to secure Data can be recovered or bento System can properly be used in case of disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly