Chater 4 Mod3: Understanding Network Security Infrastructure Flashcards
What are the two primary options for organizations in terms of managing data centers?
Organizations can either outsource the data center or own it. If owned, the data center is likely to be built on premises, meaning it is physically located within the organization’s facilities.
What are some critical components and considerations for on-premises data centers?
On-premises data centers require facilities such as buildings, power supply, Heating, Ventilation and Air Conditioning (HVAC) systems, and fire suppression. These components are essential for the proper functioning and security of the data center.
Why is the protection of the physical layer of the network important for data center security?
Protecting the physical layer helps minimize intentional or unintentional damage to the data center. It involves securing access to areas containing critical infrastructure, such as phone and network connections, ISP or telecommunications equipment, servers, and wiring or switch components.
What are the environmental considerations for maintaining data center equipment?
Environmental considerations include maintaining proper cooling and airflow, with temperature standards ranging from 64° to 81°F (18° to 27°C). Contaminant control, monitoring for leaks, and planning for contingencies in case of system failures are crucial aspects of environmental management.
Why is power supply critical for data centers, and what measures are taken to ensure constant and consistent power?
Data centers consume a significant amount of electrical power, requiring constant and consistent delivery. Backup generators and battery backups are used to ensure power continuity, with proper sizing and testing to support the critical load and infrastructure during power disruptions.
How is fire suppression addressed in server rooms, and why is water usage a concern?
Fire detection/suppression in server rooms is based on room size, human occupancy, egress routes, and equipment risk. Water usage is a concern because it can cause harm to servers and electronic components. Gas-based fire suppression systems, though more electronics-friendly, may pose toxicity risks to humans.
What is the fundamental concept behind redundancy in system design, particularly in the context of data centers?
To have duplicate components to ensure system reliability in case of failure.
How does redundancy apply to power supplies in a data center environment?
Devices should ideally have two power supplies connected to diverse power sources for backup.
In the realm of data centers, when might it be necessary to establish multiple separate utility service entrances?
It is necessary for redundant communication channels and mechanisms.
What additional steps are taken for power source redundancy in a high-availability environment, especially concerning generators?
Generators are made redundant and fed by different fuel types.
For devices in a data center to achieve full redundancy, what is the recommended power supply configuration?
Two power supplies should be connected to diverse power sources.
What does a redundant power source provide in addition to redundant backups of information in a data center?
An uninterrupted power supply (UPS).
What components might be involved in ensuring a constant power supply in a data center, besides redundant backups and generators?
Transfer switches or transformers.
Why is a backup generator considered essential in data centers?
To provide power in case of interruptions due to weather, blackouts, or other factors.
In a high-reliability setup, what is the configuration for backup generators, and why?
Two generators connected by two different transfer switches to ensure redundancy.
What are the different fuel sources that can power backup generators in a data center?
Diesel, gasoline, propane, or even solar panels.
How might critical organizations like hospitals or government agencies implement redundancy in their power sources?
They might contract with more than one power company and be on two different grids.
Explain the purpose of agreements like Memoranda of Understanding (MOU) or Memoranda of Agreement (MOA) in the context of business continuity and disaster recovery.
MOUs or MOAs are agreements between organizations to share resources during emergencies, ensuring the maintenance of critical functions.
Provide an example of how competitors, like hospitals, might collaborate through agreements such as JOA or MOU for business continuity.
Hospitals, may create agreements to share resources during emergencies, allowing them to operate in each other’s facilities to maintain critical functions.
What factors might lead organizations to enter into joint operating agreements (JOA) or similar agreements with their competitors?
Organizations might collaborate with competitors to leverage facilities and resources, meeting industry needs for business continuity.
Differentiate between Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA) and Service Level Agreement (SLA) in terms of their focus and specificity.
MOUs or MOAs are more related to what can be done with a system or information, while SLAs specify intricate details of services.
Describe the level of detail covered in a Service Level Agreement (SLA) by providing an example of a specific requirement mentioned in an SLA.
SLAs specify detailed aspects of services, such as requiring two full-time technicians available from Monday through Friday from eight to five for IT services.
Explain the caution and considerations needed when outsourcing IT services with cloud-based providers, particularly concerning SLAs.
Caution is required to understand the specifics of SLAs, ensuring clarity on factors like accessibility to information and relying on legal teams for thorough review.
If a Service Level Agreement (SLA) promises 100 percent accessibility to information, what cautionary steps should be taken to clarify the terms?
It’s important to clarify whether the 100 percent accessibility is direct to the client or through the provider’s website or portal during specific times, requiring careful legal review.