Cloud Security Flashcards

1
Q

What is a public cloud?

A

Service provider controls all aspect of the network and resources. You just get access to it.

Service provider owns:
Hardware
Software
Supporting infrastructure

Your interaction:
Web browser access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the biggest risk when using public cloud?

A

You are sharing everything but everything is virtually isolated from each other. So one traffic does not cross connect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a private cloud?

A

Exclusive to a business or organization.
You can set up onsite or by a service provider. You do not SHARE ANYTHING with anyone else. It is more secure and public.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Hybrid cloud?

A

Best of both:
Cloud-base resources
onsite resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is community cloud?

A

Shared cloud infrastructure for multiple organization.

Easy to collaborate with other organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a SaaS?

A

Is a cloud computer model - Ready to use application with least management support on organization

Provider’s responsible for:
Infrastructure
Host and manage end user application
Application / Security / Database/ OS/ Networking

Organization’s responsible for
Security of the data (regulations, compliance)
User access
Understand how data is stored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is PaaS?

A

Platform as a Service. - Pay as you go or on demand

Provider controls:
Host infrastructure, manages OS

Organization controls
the actual applications running or being created and the security aspect of controlling user access and how data is secure.
Responsible for security patches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is IaaS?

A

Infrastructure as a service - service model -

Provider controls
Host the infrastructure

Organization
Application running on the OS and security
Security (patching and user access)
Database
Operating system running now

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is XaaS?

A

Is a generic all-encompassing term for a variety of cloud services like:

Desktop as a service - DaaS
Database as a service - DBaaS
Disaster Recovery - DRaaS
Monitoring - MaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Edge and Fog computing?

A

They help improve performance when dealing with cloud base solutions.

Helps with Latency.

We are moving the processes closer to the end user.
Enhance realtime processing
Alleviate network congestions.

Edge: servers closer to edge devices

Fog - IOT devices that need low latency. Fog is closer than edge to the IOT.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a MSP?

A

Managed Service Providers - remotely manages a customer’s IT infrastructure

Typically follow a subscription model
May manage on premises or off premises resources
Can reduce cost for organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a MSSP?

A

Managed Sevice Security Providers are MSPs that focus on security.

May provide soft services such as training, risk assessments, and auditng

Often provides and manage technical solutions such as firewalls, IPS, anti-malware, VPNs, ACLs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a virtual machine?

A

Software base emulation of a computer that runs on physical hardware. It is an isolated environment that you can run different applications.

Essentially you are virtualizing physical servers now.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a container?

A

Virtualizes 1 OS so now you can put each app in its own “container”. You can then move containers along just as long as there is a supported container engine running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a VM escape?

A

Potential security breach where the attack has access to the host operating system. You can now leave isolated environment.

Patch the hypervisor at all times and have ACLs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a VM Sprawl?

A

The accumulation of unnecessary or unmaintained VMs in your environment.

You need to TAG each VM so you can identify everything.

17
Q

What is VM image vulnerabalities?

A

Vulnerabilities in the application software and code that needs to be patch.

PATCH PATCH PATCH EVERYTHING!

18
Q

What is a transit gateway?

A

It allows connecting different Virtual private clouds (VPC) and on premises resources.

Consolidate all inbound connections then forward it outbound correctly.

19
Q

What is VPNs?

A

Virtual Private Network

A secure connection between your on premises datacenter and your cloud resources.

20
Q

What is Auto-Scaling

A

The ability to automatically adjust the number of resources needed to meet the demand of the users.

Only run what you need.

21
Q

What is serverless?

A

Run code directly in the cloud without having to manage, monitor, maintain or secure servers.

22
Q

What is a Web application firewall (WAF) used for?

A

To inspect http and https traffic to and from your web servers.

You can uncover web base attacks - SQL injections / x-site attacks

23
Q

What is a Secure Web Gateway (SWG)?

A

Physical or virtual device that protects corporate users from web base threats and enforces corporate acceptable use policies.

THIS IS A PROXY

Does URL filtering / malicious content inspections

Traffic needs to flow through this traffic.

24
Q

What is a Cloud Access Security Broker (CASB)?

A

Is designed for SaaS applications. On premises or cloud.

Places between the cloud base service consumer and provider and it interjects the security policies as SaaS.