Chapter 6 Flashcards

1
Q

NIST

A

National Institute of Standards and Technology

created Three service models

  • Note like the ISO only the acronym makes sense
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST Service Models

A

SaaS - Software as a Service
PaaS - Platform as a Service
IaaS - Infrastructure as a Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Private Cloud

A

The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers. It may be owned, managed, and operated by the organization, a 3rd party, or some combination of them, and may exist on or off premises

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Public Cloud

A

The cloud infrastructure is provisioned for open use by the general public. It may be owned, managed, and operated by the business, academic, or government organization, or some combination of them. It exists on the premises of the cloud provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Community Cloud

A

The cloud infrastructure is provisioned for exclusive use by a specific community of consumers from organizations that have shared goals. It may be owned, managed, or operated by one or more of the organizations in community, a third party, or some combination of them, and it may exist on or off the premesis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Hybrid Cloud

A

The cloud infrastructure is a combination of two or more distinct cloud infrastructures that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Two methods of virtualization implimentation

A

Type I Hypervisor Model
- Aka Bare Metal, is independant of the operating system and boots before the OS

Type II Hypervisor Model
- AKA Hosted is dependent on the operating system and boots within it (like we did in class)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Snapshots

A

Allow you to take an image of a system at a particular point in time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Patch Compatability

A

Need to make sure that your virtual technology is as up to date as your OS to ensure compatability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SLA

A

Service level agreement

Goal 99.999% uptime. Host availability is a major factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SCT

A

Security Control Testing

Interviews, examinations, and testing systems to look for weaknesses. It should include contract rules from the SLA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sandboxing

A

Running Apps within restricted memory areas. Prevents “server hop”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Laws and Regulations in regards to cloud security

A

The customer retains the ultimate responsibility for compliance. Cloud server is not responsible for user error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Multitenancy

A

Many different clients sharing the same cloud server. Could be a security issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SaaS

A

Software as a Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Paas

A

Platform as a Service

17
Q

IaaS

A

Infrastructure as a Service