Security II Flashcards

1
Q

CSPs build clouds not only on a technical level but also on a level of trust and security (T/F)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CSPs have to build trust by providing a reliable and secure environment (T/F)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the user’s role in security?

A

You own the data thus it is your responsibility to protect your data and yourself from noisy neighbors and threat vectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Trust the vendor to do everything (T/F)

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Rely on vendor security measures as your be-all end-all (T/F)

A

Flase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Don’t discount your on-prem infrastructure (T/F)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why is securing on-prem important?

A

It has direct links to the cloud and is often forgotten. Addressing internal threats might require additional personnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some common pillars of trust between CSP and customer?

A
Security
Privacy
Control
Compliance
Transparency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Security and what are some examples?

A

The ability to safeguard data and access. Examples are: Encryption, Data Retention, Internal Policies, Antivirus, Identity Management, Access Management, Logging.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Privacy?

A

Ensuring your data is only used for the purposes defined in policies and preventing unauthorized use and access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Control?

A

Controlling the exchange, flow, and retention of data as well as authorization and auditing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Compliance?

A

Ensuring compliance with industry standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Transparency?

A

Considered the most important pillar, it is the honesty, openness, and accountability of the provider. Examples: describe data safeguards, security measures, policies on data, security and access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are security standards for SaaS?

A

CSP: Secure infrastructure, secure OS, application layer, secure data between CSP and customer.
Customer: Control data, control access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are security standards for PaaS?

A

CSP: Secure infrastructure, secure OS, application layer, secure data between CSP and customer.
Customer: Control data, control access, control all code and development environment settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are security standards for IaaS?

A

CSP: Secure infrastructure
Customer: control OS/virtualized infrastructure, control data, control access.

17
Q

Internal threats are higher than external threats (T/F)

A

True