Section 1 - Design Secure Cloud Solutions Flashcards
At the end of the day, cloud security enables
Decreases attack surface
Compliance
Standardization and Best practices
Multi Cloud is
AWS and Azure and for features and pricing
Community Cloud
Shared resources and typically universities and thinktanks. Also gaming communities can follow under this
What is the core crucial security task of a CSP
Preserving Isolation
What additional elements is not included in the CIA Triad
Privacy - a valid concern based on regulations
Auditability
Regulatory Oversignt
What are some major concerns clients should have with moving to the Cloud
Reversibility - can you reverse the move
Avoid Vendor Lock In
Interoperability
What is the technical discipline designed to apply the principles of Data Science and statistics to uncover knowledge hidden in the data we accumulate every day
Machine Learning
Machine Learning is a subset of a broader field called _______ which has the following goals
AI
Descriptive Analytics
Predictive Analytics
Prescriptive Analytics - Optimize our behavior
What is the technology called that is in essence a secure distributed and immutable ledger and what drove its creation and use
Block Chain
BitCoin
NIST 800-53 3 Control Implementation Approaches
Common (inheritable)
System Specific
Hybrid
What organization produces the STAR Report and for what purpose
Cloud Security Alliance (CSA)
Security, Trust, Assurance and Risk Registry
Name some common Container Repositories
Docker Hub - Public
Docker Trusted Registry - Private
Azure Container Registry - Private
Name the 3 Block Storages for each Azure, AWS, and Google
AWS - S3 Buckets
Azure Blob Storage
Name some of the best practices for monitoring AWS Virtual Private Cloud (VPC)
Enable CloudWatch Logs
Use AWS Cloud Trail to monitor VPN Configs
Enable VPC Flow Logs
You can also use Amazon Guard Duty to detect anomalous behavior
What is the name for AWS DNS Services and what is the Amazon service for analyzing DNS Logs
Amazon Route 53
Amazon Guard Duty