Cloud Infrastructure Assessments Flashcards

1
Q

Data received by an API must pass service-side validation routines

A

Insecure Application Programming Interface (API)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

APIs should use secure authentication and authorization such as SAML or
OAuth/OIDC before accessing data

A

Improper Key Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Logs must be copied to non-elastic storage for long-term retention

A

Insufficient Logging and Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cloud storage containers are referred to as buckets or blobs

A

Unprotected Storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A content delivery network policy that instructs the browser to treat requests
from nominated domains as safe

A

Cross Origin Resource Sharing (CORS) Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A virtual machine that is created and configured for a particular purpose and then
shut down or even left running without properly decommissioning it

A

Dormant VM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An open-source tool written in Python that can be used to audit instances and
policies created on multicloud platforms, including Amazon Web Services,
Microsoft Azure, and Google Cloud Platform

A

ScoutSuite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An auditing tool for AWS that is used to evaluate the cloud infrastructure against
AWS benchmarks, GDPR compliance, and HIPAA Compliance

A

Prowler

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

An open-source cloud penetration testing framework to test the security
configuration of an AWS account

A

Pacu

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Attacker’s may use multicloud services to create their attack platform

A

Cloud Forensics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly