Cloud Security Flashcards

1
Q

On-Premises

A

Operates locally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Off-Premises

A

Operates via the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CTSS

A

Compatible Time-Sharing System
Distributes resources of a single machine for simultaneous multiple user access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IaaS

A

Infrastructure as a Service
Maintaining server on a cloud-based VM
Provides virtual resources
Customer Responsible for: Accountability, Data, Application, Runtime, Middleware, OS
Provider Responsibility: Virtualization, Servers, Storage, Network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PaaS

A

Platform as a Service
Creation of platforms for applications & eliminates platform maintenance
Customer Responsible for: Accountability, Data, Application
Provider Responsibility: Runtime, Middleware, OS, Virtualization, Servers, Storage, Network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SaaS

A

Software as a Service
Running software off-premises (Ex. Dropbox, Gmail, Office365)
Customer Responsible for: Accountability, Data
Provider Responsibility: Application, Runtime, Middleware, OS, Virtualization, Servers, Storage, Network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

XaaS

A

Anything as a Service
All types of products that can be provided via the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DaaS

A

Desktop as a Service
Hosting an OS on a virtual machine
Provide desktop interfaces for users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Public Cloud

A

Uses provider resources
Hosts services open to others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DRaaS

A

Disaster Recovery as a Service
Replication of servers to the cloud (failover solution)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Private Cloud

A

Separate for each customer
Private customizable environment
Offers a higher level of reliability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Hybrid Cloud

A

Public and private models combined
Running apps interchangeably, privately,
or publicly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Hypervisor

A

Manages virtual system resources
Type 1 runs on system hardware (also known as bare metal)
Type 2 runs on host OS as an application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Virtualization Security

A

Cloud Provider Responsibility: physical infrastructure security and virtualization platform security
Cloud Customer Responsibility: Virtualized security controls (virtualized host encryption)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cloud Availability Zones

A

Regions: Multiple availability zones
Availability Zones (AZ) : Geographical (closer is better), Legal/compliance/corporate policy constraints of where data resides, Cost, Offerings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SLA

A

Service Level Agreement
Agreement between service provider and client regarding the features provided and implementation

17
Q

IAM

A

Identity & Access Management
Framework for management of control of permissions, authentication, and identification using digital identities

18
Q

Data Center Disaster Recovery

A

Redundancy
Resiliency
Disaster Recovery
Data Backups

19
Q

EC2

A

Amazon cloud computing service platform

20
Q

S3

A

Amazon data storage services

21
Q

POLP

A

Principle of Least Privilege

22
Q

WAF

A

Web Application Firewall
Helps protect web applications by filtering and monitoring HTTP traffic
Uses ACLs
Layer 7

23
Q

NGFW

A

Next Generation Firewall
3rd generation firewall that provides capabilities beyond a traditional

24
Q

Volumetric Attacks

A

Focus on consuming network resources through amplification or botnets.

25
Q

SDN

A

Software-Defined Networking
network architecture approach that enables the network to be intelligently and centrally controlled, or ‘programmed,’ using software applications

26
Q

SDP

A

Software-Defined Perimeter
Authentication outside app
Layer 2

27
Q

Virtualization

A

Single physical machine for multiple simulated environments.
Based on images
Lifespan: year/long-term

28
Q

Cloud Computing

A

Pool and automate resources for on-demand use.
Based on templates
Lifespan: Max hours to months/short-term

29
Q

VA

A

Virtual Appliances
IaaS: VAs are crucial regarding file format (OVA, OVF). Can be network devices (routers, switches)
SaaS: VAs provide direct route when a quick SaaS setup is needed. Prevent the need to redesign large apps.

30
Q

Container

A

Standard units of software packaging code and dependencies
Lightweight/standalone
Ensure secure implementation of apps

31
Q

Docker

A

A PaaS that uses virtualization to deliver software in containers

32
Q

SDP Core Pillars

A

Identity-Centric: identities rather than IP addresses
Zero Trust: Must authenticate first
Build for the Cloud: Works w/ SDN & prevents unauthorized network access

33
Q

DLP

A

Data Loss Prevention

34
Q

CASB

A

Cloud Access Security Broker
Gatekeeper and manages security-related policies