Domain 2 Flashcards
What is the MTD metric
Maximum tolerable downtime
What is scalability
Capacity to increase resources to meet demand within similar cost ratios
What are the two types of scalability
Scale out to add more resources in parallel
Scale up to increase power of existing resources
What does elasticity refer to
The ability to handle scalability changes in real time
A power distribution unit is like what?
Like a surge protector
Raid 0
Striping performance gain no redundancy
Raid 1
1 disk failure redundancy in 2 disk setup
Con is low storage efficiency 50%
Raid 5
Min 3 disks
Striping with parity
One disk can fail
Raid 6
Min 4 disk
Double parity
Min 4 disks
Can have 2 disks fail
Raid 10 nested
Striped set of mirrored subgroups
Faster speeds
Each subgroup can have one failure disk
Raid 50
Min 6 drives
Striped set of parity subgroups
Each subgroup can lose one disk
Multipath provides what that raid doesn’t
Raid deals with drive failures
Multipath deals with storage path such as bus controllers and multiple network paths to storage devices
Geographical dispersal
Data replicating hot and warm sites physically distant from each other
3 2 1 backup rules
3 copies 2 different media 1 offline and 1 off-site
What is a master image
Copy that has os up to date, all patches, and software installed
What is automated build from template?
Build instructions for an instance
What does layered security provide
Defense in depth
What port does ldaps and ldap use?
Ldaps Port 636
Ldap port 389
Why is snmp v1 and v2c not secure
Sends community string in plaintext
What security benefit does snmp v3 provide
Supports encryption and strong user based authentication
What does tls 1.3 remove which makes it now more secure
Ability to downgrade to lower SSL levels
In Tpm can endorsement key be changed?
No it cannot be changed
What is difference between measured boot and boot attestation
Measured boot measures boot process to report on any potential malware
Boot attestation sends a log signed by Tpm to report any issues like unsigned drivers
In a cookie what does the httponly attribute do?
Prevents dom based attacks and client side scripting
In a cookie what does the same site attribute do
Control from where cookie may be sent protecting against request forgery attacks
What does hsts do in web browsers?
Prevents downgrading to http and sslstripping