Security I Flashcards
Why do hackers target clouds?
Clouds are a treasure trove of information
What are DDOSs?
Attacks which come from multiple resources that consume all resources
How to defend a cloud?
Don’t rely on security measures as a be-all end-all solution
Implement encryption
Don’t store passwords using reversible encryption
Don’t store sensitive information in the cloud
Check for vulnerabilities
Security measures are cheaper when implemented on a mass scale (T/F)
True
Cloud providers often hire security experts and subject matter experts (T/F)
True
Deployment of security updates tends to be much quicker (T/F)
True
There are both internal and external threats (T/F)
True
Cloud providers ultimately focus on individuals (T/F)
False. They focus on securing for the greater good.
What are some important security safeguards?
Auditing Vulnerability testing Independent pen-testing Defined policies Allow users to set own policies (user-level data security) VPNs
PCI DSS
Payment Card Industry Data Security Standard
Certification that ensures that the provider can handle payments
Provider has to undergo audits and protect data
SOC 2 Type 2
Service Organization Controls
Ensures data security at the highest level
Involves long-term testing
SOC 1 is for less comprehensive systems (T/F)
True
SOC2 is for more comprehensive systems (T/F)
True