Secure Design Architecture - The Cloud Flashcards

1
Q

What common strategy have many organizations adopted regarding cloud services?

A

A cloud-first strategy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does NIST generally define cloud computing?

A

A model for ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources provisioned with minimal effort.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name the three primary cloud service models mentioned.

A

Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What term describes the trend of offering many types of services via the cloud?

A

Everything as a Service (XaaS).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a public cloud deployment model?

A

Resources are shared among multiple organizations/public users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a private cloud deployment model?

A

Resources are dedicated to a single organization’s use (essentially a private datacenter).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a community cloud deployment model?

A

Resources are shared by several organizations with common concerns (e.g., universities).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a hybrid cloud deployment model?

A

A combination of two or more different cloud deployment models (e.g., private and public).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What advantage does SaaS offer regarding software updates and patches?

A

The provider manages updates centrally, ensuring all users have the same version without individual machine updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can cloud adoption impact environmental footprint?

A

It can reduce the footprint by consolidating multiple organizations into fewer, more efficient datacenters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What benefit does cloud offer regarding administration?

A

Centralized administration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What advantage might cloud providers have regarding staffing?

A

They often employ skilled staff with broad experience supporting many clients, expertise individual organizations may lack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How might cloud providers achieve cost advantages in hardware?

A

Through bulk purchasing power.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a risk if a cloud provider ceases operations?

A

Loss of service and potential loss of data access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What risk is associated with relying on network access to the cloud?

A

Loss of connectivity means loss of access to services and data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What potential issue arises from where a cloud provider stores data?

A

Data might be stored in a jurisdiction that violates cross-border data privacy laws applicable to the customer.

17
Q

What type of control do organizations often lose when moving data to the cloud?

A

Direct control over the data’s location, security, and lifecycle management.

18
Q

What concern exists regarding data deletion by cloud providers?

A

Uncertainty about whether data is properly and securely erased when requested or after contract termination.

19
Q

Who typically controls encryption keys in a SaaS environment, and what is the implication?

A

The cloud service provider often controls the keys, meaning they technically have access to the customer’s data.

20
Q

What issue can make migrating away from a cloud provider challenging?

A

Vendor lock-in, where moving data and rebuilding infrastructure is difficult, potentially due to proprietary data formats.

21
Q

What critical step must be taken when adopting any cloud solution?

A

Evaluate it critically for security concerns and ensure requirements are addressed.

22
Q

Where should security requirements for cloud services be formally documented?

A

In contracts and Service Level Agreements (SLAs) with the provider.