Infosec Key Terms Domain 1 Flashcards

1
Q
  • Capital Expenditure
  • Operational Expenditure
  • Elasticity
  • Mobility
  • Scalability
A
  • Capital Expenditure - this is lowered when moving to cloud; i.e. Hardware, buildings, equipment
  • Operational Expenditure - this is also lowered when moving to cloud; i.e. utility costs, maintenance
  • Elasticity - ability to grow or shrink IT assets (i.e. # of users) without excess
  • Mobility - being able to access cloud from anywhere
  • Scalability - ability to increase of decreases services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST 5 Basic Characteristics of Cloud Computing (BRO-ME) +1 from ISO

A
  1. Broad network access - ability to access cloud via any platform (i.e. mobile, web browser) regardless of user’s location
  2. on-demand services - cloud is always on and accessible; able to +- storage with little to no intervention with CSP
  3. resources pooling - cloud provider able to scale resources to each customer as needed
  4. measured service - only pay for what you use
  5. rapid elasticity - cloud increase or decrease resources on its own
  6. Mult-tenancy - several customers on one device but are seperated by design
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Concerns moving to cloud (5)

A
  1. Security
  2. Privacy
  3. Compliance
  4. Interoperability
  5. Lock-ins
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IPS Elements

A
  1. IaaS - Block storage, compute, network
  2. PaaS - Database, Object Storage, Identity, Software Testing, Runtime, Queue
  3. Application - Monitoring, Content, Collaboration, Communication, Finance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  1. Cloud Customer vs Cloud User
  2. Cloud Service Broker
  3. Cloud Service Provider
  4. Managed Service Provider
A
  1. Cloud Service Broker - liasion between customer and provider; looks to extend or enhance value to customers who are looking to move to cloud
  2. CSP - the vendor offering the services; the provider DICTATES the technology and operational procedures
  3. Managed Service Provider - CONSUMER dictates the techonlogy and operating procedure (usually has a NOC)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IaaS

A
  1. Most basic cloud service offering; customer has ability to install all software including OS
  2. Customer has most control

Benefits
1. Pay for what you use
2. scalability
3. reduced cost of ownership
4. Reduced Energy and cooling costs with GREEN IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

PaaS

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SaaS

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Building blocks of cloud computing

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  • Containers
  • Mutable infrastructure
  • Immutable
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Public Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Private Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Community Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Hybrid Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Hypervisor Type 1 and Type 2 Overview

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Hypervisor Type 2 Risks

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Define Virtualization and the primary drivers

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Security Controls in Virtual Environment
1. Trusted Zones
2. Snapshot
3. Customer retain responsiblity to implement:

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Management Plane

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Scalability vs Elasticity

A

Scalability vertical and scale up - moving application to a bigger VM to handle load

Scale horizontal and scale out - placing application on multiple VMs and distribute the load

21
Q

IAM
1. Identification
2. Authentication
3. Authorization

22
Q

Provisioning
* Type 1 authentication
* Type 2
* Type 3

23
Q

Authorization

24
Q

IAM Lifecycle

25
Q
  • Most widely used directory service is
  • Briefly go over OSI Model
  • TCP / IP model
26
Q

Deprovisioning

27
Q
  1. Privileged Accounts
  2. CASB
28
Q

Federated Identity Management

29
Q

SSO vs RSO

30
Q

Functional vs Nonfunctional Requirement

31
Q

BIA has 3 primary goals

32
Q

Risk Assessment

33
Q

Define Threat

34
Q

Define Vulnerability

35
Q

How is Risk Determined

36
Q

Quantitative vs Qualitative

37
Q

Tangible Assets vs Intangible Assets

38
Q

Asset Valuation
* absolute value
* relative value
* fair market value

39
Q

Determining Criticality

40
Q

SPOFs

41
Q

Risk Appetite

42
Q

Cloud Computing Service Models

43
Q

Cloud Service Model Boundaries

44
Q

IaaS boundaries

45
Q

PaaS Boundaries

46
Q

SaaS Boundaries

47
Q

Protecting Sensitive Data

48
Q

What are the types of blockchain