Lesson 6: Cloud Security Flashcards

1
Q

A practice of delivering hosted services, which can be software as a service, platform as a service, or infrastructure as a service, over the Internet.

A

cloud computing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A cloud service model where the cloud service provider (CSP) provides software applications.

A

software as a service (SaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A cloud service model where vendors provide hardware capacities, such as compute, storage, or networking, to a client.

A

infrastructure as a service (IaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A cloud service model that includes operating systems and software development tools, such as runtime environments.

A

platform as a service (PaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A cloud deployment model where a client owns and operates all cloud equipment and services.

A

private cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The most familiar cloud model where public companies own cloud resources and sell them to clients.

A

public cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A cloud deployment model where multiple organizations with similar interests band together for cloud services.

A

community cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A cloud deployment model where one part of the cloud is public and the other part is private.

A

hybrid cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A piece of software that enables virtualization on a computer.

A

hypervisor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The infrastructure that is represented in an imperative manner rather than a declarative manner.

A

infrastructure as code (IaC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The ability to develop and/or adopt new technologies at a much faster rate than organizations attempting to build their own infrastructures is known as

A

Disruptive Innovation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The process of automating the provisioning, management, and deprovisioning of infrastructure services through scripted code rather than human intervention.

A

Infrastructure as code (IaC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  • Increasing the reusability of code
  • Increasing the speed of infrastructure creation
  • Reducing the likelihood of configuration errors by leveraging common templates
A

The major advantages to using an IaC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

______ is an AWS-specific exploitation framework. It is particularly well suited to identifying the permissions available to an account during a penetration test.

A

Pacu

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which cloud assessment tool performs security scans of Microsoft Azure cloud environments.

A

ScoutSuite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In the shared responsibility model, a customer always retains either full or partial responsibility for

A

data security.

17
Q

In all cloud service models how is responsibility for data center security split with the customer and cloud provider

A

Cloud service providers bear sole responsibility for datacenter security

18
Q

Which cloud computing deployment model requires the use of a unifying technology platform to tie components together from different providers?

A

Hybrid

19
Q

What does Inline cloud access security broker (CASB) solutions intercept requests from users to cloud providers and, by doing so, these can both

A

monitor activity and enforce policy requirements.