RISK Flashcards
RISK by Svc Models
What Risk is addressed by SaaS?
What (4) environments are affected?
Consumer – Multi-Tenants may share same applic stack ie: (4)
WEB, DB, APP, Ntwk
RISK by Svc Models
What Risk is addressed by PaaS?
Build – Vuln in Platform stack BLEEDS sharing data BU, archives
RISK by Svc Models
What Risk is addressed by IaaS?
HOST – Cross Ntwk traffic listeners find host less hardened/ptch’d other Tenants
What are 5 characteristics of Cloud? BORRM
Broad Network Access – On Demand Svc – Rapid Elasticity – Resource Pooling – Measured Svc Pay-as-Go –
As part of a cloud provider’s services, customers can provision a new virtual machine as needed without human interaction with the provider. This scenario is BEST described by which of the following cloud characteristics?
A. On-demand self-service
B. Measured service
C. Broad network access
D. Rapid elasticity
A. On-demand self-service
Which of the following is the MOST important service management consequence of elastic capacity?
A. The need for better application development
B. The need for better security management
C. The need for good performance monitoring and management
D. The need to improve the fulfillment and provisioning process
C. The need for good performance monitoring and management
Which of the following is the MOST important impact of cloud computing on managing service levels?
A. Capacity can be more elastic.
B. External providers can deny a capacity increase when required.
C. Providers measure their own performance.
D. Scarcity of resources can occur if not monitored
A. Capacity can be more elastic.
Which of the following does IT outsourcing and cloud computing typically have in common?
A. Pay as you go agreements
B. Short-term financial commitment
C. Tailor-made applications based on client needs
D. Vendor lock-in potential
D. Vendor lock-in potential
What type of attack is Heartbleed ?
How is it detected?
What does it affect?
RAM read attack – OPEN SSL – Detects heartbleed TLS used – network session keys
What type of attack is Petya?
What does it target?
What does it do?
Ransomware - WIN MB Record - Encrypts HDD prevents WIN reboot
Encrypts Ransomware – Target WIN MB Rec. Encrypts HDD Prevents WIN Boot
What type of attack is Wanna Cry?
What does it target?
What type of vulnerability?
Ransomware – Target WIN - Crypto Worm
What type of attack is Poodle?
What does it target?
what type of weakness does it attack?
PAD Oracle - SSL 3.0 - MitM plain txt
PAD Oracle on Downgrade Legacy Encryption – Target browser relies on SSL 3. 0 Protocol weakness allows MiTM attack to see plain txt content
What is Broad Netwk Access?
Cloud benefit: Available by phone, PC, anywhere
What is On Demand Service?
Request what you need, when you need it: Server, Storage, automated
What is Rapid Elasticity?
Rapid provision. Scale IN / Scale OUT