Cloud Concepts Architecture and Design Flashcards
What are the main part of the NIST cloud definitions ?
Cloud has five essential characteristics, three service models and four deployment models
What are the essential characteristics of the cloud ?
- Broad Network
- Access Resource Pooling
- Multitenancy
- Rapid Elasticity and Scalability
- Metered Service
- On Demand Service
What is the idea behind the concept of orchestration in the Cloud ?
It is mainly the responsibility of the Cloud Provider to provide access to the cloud without forcing cloud customer to adopt vendor specfic components such as browser plugins.
What is the function of the hypervisor in virtualization ?
To allocate CPU and RAM
What are the two types of hypervisor ?
Type 1 : Bare Metal - Runs on Hardware no OS
Type 2: Runs on the OS
What is guest escape ?
The ability in a multi tenanted environment to access other customers data or software
What is resource pooling ?
Characteristic that allows the cloud provider to meet various demands of customers while remaining financially viable.
What are five cost benefits from moving to cloud.
- Reduction in Capital Expense
- Reduction in Personnel Costs
- Reduction in Operation Costs
- Transfer of Regulatory Costs
- Reduction in Archival and Backup costs
What is a capital expense ?
If an Organisation buys a server for example then that is a capital expense and the company is going to incur a cost from either under utilisation or under capacity. Because buying a service is an operational expense some of this cost is tax deductible as a legal expense.
What is the benefit of reducing Personnel costs ?
IT Personnel are expensive to hire and train. By switching to the cloud you can offload some of this expense to the cloud provider.
What is the advantage of regulatory transfer costs ?
Some cloud providers will be compliant in their hardware setup for example against certain standards such as PCI DSS this means the cloud customer can save this cost and concentrate on making other areas compliant such as their processes.
As a cloud customer can I transfer my PII data responsibility to the cloud provider ?
No ultimately the cloud customer is still responsible for PII data. There may be cases where the cloud customer can sue the provider if they can prove negligence but they are still responsible.
What is the difference between elasticity and scalability in Cloud computing ?
Elasticity is about handling short term fluctuations in demand whereas scalability is a more medium too long term ability to cope with increasing customer base of a company.
What is the difference between a cloud customer and a cloud user ?
A cloud customer is buying services directly from the cloud provider whereas a cloud user is using those purchased services. For example if I but a cloud enable phone app I am a cloud user not a cloud customer
What are the three main service model in the cloud ?
IAAS, PAAS, SAAS
What is IAAS ?
Most basic of the offerings basically only the machine it is your responsibility to install the OS. This is a good option if you want to have control over patching and security of the data you put on these machines.
What is PaaS ?
PaaS is where the cloud provider gives you the OS and patching and maintains a responsibility for it.
You are responsible for what you install on top of the OS. Software houses like this option as they want to develop software not maintain an OS.
What is SaaS ?
Software as a service is where you just consume the service as an end user. You have very little control on the security and placement of the data.
What is the Public cloud deployment model ?
Software as a service is where you just consume the service as an end user. You have very little control on the security and placement of the data.
What is the private cloud deployment model ?
Resources are dedicated to a single customer. It might be owned and maintained by the customer of its services but it may also be some services offered by the public cloud provider but are made available solely for that customer.
What is the community cloud deployment model ?
Cloud is owned and operated by an affinity group. People and organisations come together to perform similar tasks and operations.
An example is the Playstation network.
A community cloud can also be provisioned by a third party on behalf of members of that community.
What is the hybrid cloud deployment model ?
A combination of other deployment models
What is a cloud service broker
A company that purchases services from the cloud provider who then resells them to its own customers.
What does the role Cloud access security broker do ?
A third party entity offering independent IAM services to cloud customers
What does the term cloud portability mean >
The ability to move applications and associated data between providers
What is FIPS 140-2
Describes the process fir accrediting and describing cryptosystems for use by the federal government
What is NIST 800-53
A guidance document with the primary goal of ensuring that appropriate security requirements and controls are applied to all US Federal government information
What is the trusted cloud initiative reference model ?
A guide for cloud providers allowing them to create a holistic architecture so that cloud customers can purchase services with confidence.
What is vendor lock out
Occurs when a customer is unable to recover access to thier own data
What is vendor lock in ?
Vendor lock in when a customer is unable to leave a provider
What are the five foundation concepts for the cloud ?
- Sensitive Data
- Virtualization
- Encryption
- Auditing and Compliance
- Cloud Service Provider Contracts
Why is auditing difficult in the cloud ?
Cloud providers are extremely reluctant to allow physical access to their facilities or to share network diagrams or list of controls. Instead Cloud providers often offer an assertion of thier own audit success
What are the Cloud Service Provider Contracts
The SLAs on performance and provision snd penalties for failure to do so
What are the capacity issues for private cloud ?
A customer can exceed them
How does community cloud and regulation work ?
If a community is bound by a regulation such as HIPPAA then it makes sense for them to pay the cloud provider to create a community cloud where the infrastructure is compliant
What are the main cloud considerations ?
- Auditability
- Interoperability
- Regulatory
- Portability
- Security
- Performance
- Governance
- Privacy
- Resiliency
- Reverability
- Maintenance
- Availability
- SLAs
What is the main risk of quantum computing for security ?
Makes many brute force tasks cheap and available
For a software company moving to the cloud which is the greatest security concern multitenancy or remote access
multitenancy is the primary concern as it directly affects their core business