Section 1 - Design Secure Cloud Solutions Flashcards

1
Q

At the end of the day, cloud security enables

A

Decreases attack surface
Compliance
Standardization and Best practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Multi Cloud is

A

AWS and Azure and for features and pricing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Community Cloud

A

Shared resources and typically universities and thinktanks. Also gaming communities can follow under this

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the core crucial security task of a CSP

A

Preserving Isolation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What additional elements is not included in the CIA Triad

A

Privacy - a valid concern based on regulations

Auditability

Regulatory Oversignt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some major concerns clients should have with moving to the Cloud

A

Reversibility - can you reverse the move

Avoid Vendor Lock In

Interoperability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the technical discipline designed to apply the principles of Data Science and statistics to uncover knowledge hidden in the data we accumulate every day

A

Machine Learning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Machine Learning is a subset of a broader field called _______ which has the following goals

A

AI

Descriptive Analytics
Predictive Analytics
Prescriptive Analytics - Optimize our behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the technology called that is in essence a secure distributed and immutable ledger and what drove its creation and use

A

Block Chain
BitCoin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

NIST 800-53 3 Control Implementation Approaches

A

Common (inheritable)
System Specific
Hybrid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What organization produces the STAR Report and for what purpose

A

Cloud Security Alliance (CSA)
Security, Trust, Assurance and Risk Registry

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name some common Container Repositories

A

Docker Hub - Public
Docker Trusted Registry - Private
Azure Container Registry - Private

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Name the 3 Block Storages for each Azure, AWS, and Google

A

AWS - S3 Buckets
Azure Blob Storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Name some of the best practices for monitoring AWS Virtual Private Cloud (VPC)

A

Enable CloudWatch Logs
Use AWS Cloud Trail to monitor VPN Configs
Enable VPC Flow Logs

You can also use Amazon Guard Duty to detect anomalous behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the name for AWS DNS Services and what is the Amazon service for analyzing DNS Logs

A

Amazon Route 53

Amazon Guard Duty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Name the 3 providers CDN

A

Amazon CloudFront
Azure CDN
Google Cloud CDN

17
Q

Name the 3 providers DDoS protection services

A

AWS Shield
Azure DDoS Protection
Google Cloud Armor

18
Q

What is the equivalent of Azure ExpressRoute in AWS

A

AWS Direct Connect

19
Q

What is the NIST Security Framework for Cloud Providers

A

NIST 800-210

20
Q

What is the NIST Cloud Computing Standards Roadmap and what are the 5 major actors that should be considered when designing a secure solutions

A

NIST 500-291

Cloud Consumer
Cloud Provider
Cloud Auditor
Cloud Broker
Cloud Carrier

21
Q

What is the type of Cryptography that uses elliptical curve and what makes it appealing

A

ECC and much smaller keys

22
Q

Name the 3 Cloud Providers Long Term Storage/Archive

A

Amazon Glacier
Azure Archive Storage
Googles Coldline

23
Q

What are the hardware devices for encryption called

A

Hardware Security Module (HSM)
create, store, and manage encryption keys.

24
Q
A