Infosec Key Terms Domain 1 Flashcards

1
Q
  • Capital Expenditure
  • Operational Expenditure
  • Elasticity
  • Mobility
  • Scalability
A
  • Capital Expenditure - this is lowered when moving to cloud; i.e. Hardware, buildings, equipment
  • Operational Expenditure - this is also lowered when moving to cloud; i.e. utility costs, maintenance
  • Elasticity - ability to grow or shrink IT assets (i.e. # of users) without excess
  • Mobility - being able to access cloud from anywhere
  • Scalability - ability to increase of decreases services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST 5 Basic Characteristics of Cloud Computing (BRO-ME) +1 from ISO

A
  1. Broad network access - ability to access cloud via any platform (i.e. mobile, web browser) regardless of user’s location
  2. on-demand services - cloud is always on and accessible; able to +- storage with little to no intervention with CSP
  3. resources pooling - cloud provider able to scale resources to each customer as needed
  4. measured service - only pay for what you use
  5. rapid elasticity - cloud increase or decrease resources on its own
  6. Mult-tenancy - several customers on one device but are seperated by design
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Concerns moving to cloud (5)

A
  1. Security
  2. Privacy
  3. Compliance
  4. Interoperability
  5. Lock-ins
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IPS Elements

A
  1. IaaS - Block storage, compute, network
  2. PaaS - Database, Object Storage, Identity, Software Testing, Runtime, Queue
  3. Application - Monitoring, Content, Collaboration, Communication, Finance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  1. Cloud Customer vs Cloud User
  2. Cloud Service Broker
  3. Cloud Service Provider
  4. Managed Service Provider
A
  1. Cloud Service Broker - liasion between customer and provider; looks to extend or enhance value to customers who are looking to move to cloud
  2. CSP - the vendor offering the services; the provider DICTATES the technology and operational procedures
  3. Managed Service Provider - CONSUMER dictates the techonlogy and operating procedure (usually has a NOC)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IaaS

A
  1. Most basic cloud service offering; customer has ability to install all software including OS
  2. Customer has most control

Benefits
1. Pay for what you use
2. scalability
3. reduced cost of ownership
4. Reduced Energy and cooling costs with GREEN IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

PaaS

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SaaS

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Building blocks of cloud computing

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  • Containers
  • Mutable infrastructure
  • Immutable
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Public Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Private Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Community Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Hybrid Cloud and benefits

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Hypervisor Type 1 and Type 2 Overview

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Hypervisor Type 2 Risks

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Define Virtualization and the primary drivers

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Security Controls in Virtual Environment
1. Trusted Zones
2. Snapshot
3. Customer retain responsiblity to implement:

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Management Plane

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Scalability vs Elasticity

A

Scalability vertical and scale up - moving application to a bigger VM to handle load

Scale horizontal and scale out - placing application on multiple VMs and distribute the load

21
Q

IAM
1. Identification
2. Authentication
3. Authorization

A
22
Q

Provisioning
* Type 1 authentication
* Type 2
* Type 3

A
23
Q

Authorization

A
24
Q

IAM Lifecycle

A
25
Q
  • Most widely used directory service is
  • Briefly go over OSI Model
  • TCP / IP model
A
26
Q

Deprovisioning

A
27
Q
  1. Privileged Accounts
  2. CASB
A
28
Q

Federated Identity Management

A
29
Q

SSO vs RSO

A
30
Q

Functional vs Nonfunctional Requirement

A
31
Q

BIA has 3 primary goals

A
32
Q

Risk Assessment

A
33
Q

Define Threat

A
34
Q

Define Vulnerability

A
35
Q

How is Risk Determined

A
36
Q

Quantitative vs Qualitative

A
37
Q

Tangible Assets vs Intangible Assets

A
38
Q

Asset Valuation
* absolute value
* relative value
* fair market value

A
39
Q

Determining Criticality

A
40
Q

SPOFs

A
41
Q

Risk Appetite

A
42
Q

Cloud Computing Service Models

A
43
Q

Cloud Service Model Boundaries

A
44
Q

IaaS boundaries

A
45
Q

PaaS Boundaries

A
46
Q

SaaS Boundaries

A
47
Q

Protecting Sensitive Data

A
48
Q

What are the types of blockchain

A