0% found this document useful (0 votes)
13 views9 pages

Cloud Computing Security and Models Guide

The document consists of a series of questions related to cloud computing, covering topics such as resource pooling, service models, security, compliance, and data management. It addresses key concepts like IaaS, PaaS, SaaS, and various security measures and governance tools. The questions also explore the implications of cloud technology on data storage, encryption, and risk management.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views9 pages

Cloud Computing Security and Models Guide

The document consists of a series of questions related to cloud computing, covering topics such as resource pooling, service models, security, compliance, and data management. It addresses key concepts like IaaS, PaaS, SaaS, and various security measures and governance tools. The questions also explore the implications of cloud technology on data storage, encryption, and risk management.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Which technology is generally required to build resource pools?

a. Virtualization
b. CPU and memory
c. The Internet
d. VLANs
Which of the following is NOT a key potential benefit of cloud computing:
[Link]
[Link]
[Link]
[Link]
What is the key difference between traditional virtualization and cloud?
[Link]
[Link] virtualization software
[Link]
[Link]
Which of the following is not an emergent property of resource pooling?
[Link]
[Link]
[Link]
[Link] Network Access
Which service model would a cloud database be considered?
[Link] as a Service
[Link] as a Service
[Link] as a Service
[Link] as a Service
Which of the following is most likely to be considered laaS:
a.A container registry
b.A cloud message queue
[Link] cloud's management console
d.A virtual machine
In laaS, individual virtual machines use which kind of storage?
[Link]-based hardware
b.A database platform
[Link] local hard drives on the servers
[Link] volumes from a storage pool
Which of the following is not required to be considered SaaS?
[Link] physical hardware
[Link] management of the underlying resources
[Link] essential characteristics
d.A complete application
In which service model does the cloud consumer have the least amount of
control over security?
[Link] as a Service
[Link] as a Service
[Link] as a Service
[Link] as a Service
In which cloud service model is the cloud consumer responsible for ensuring
that the hypervisor is not vulnerable to attack?
[Link] as a Service
[Link] as a Service
[Link] as a Service
[Link] of the above
Which of the following resource pools is not associated with laaS:
[Link]
[Link]
[Link]
[Link]
Why is hardening infrastructure components so important?
[Link] are sometimes based on common components that may contain
vulnerabilities
[Link] security is important
[Link] components are most likely to be exposed to cloud consumers
[Link] prevents the cloud provider from accessing cloud consumer data
Which of the following physical networks is used for Internet to instance
traffic?
[Link]
[Link]
[Link]
[Link]
Why should cloud providers use multiple underlying physical networks?
(select all that apply)
[Link] management
[Link]
[Link] performance
[Link] isolation
Which virtual network technology is best suited for cloud?
[Link]
[Link]
[Link] Ring
d.V-flow
Virtual networks:
[Link] more flexible, but more difficult to secure
[Link] fewer resources
[Link] for physical networks
[Link] include inherent security capabilities
Which is a defining characteristic of Software Defined Networks
[Link] OpenFlow
[Link] the control plane from the underlying physical network
[Link] packet tagging
[Link] for resiliency
Which SDN security capability often replaces the need for a physical or virtual
appliance?
[Link] deny
[Link] of support for packet sniffing
[Link] groups
[Link] isolation
Which of the following is the most effective security barrier to contain blast
radius?
[Link] account/project/subscription
[Link] subnet ( with or without ACLs )
[Link] network
[Link] group
How does a virtual network affect network visibility?
[Link] SDN can provide more visibility than a physical network
[Link] machines on the same physical host don't use the physical
network
[Link] networks block packet capture for better isolation
[Link] networks always encrypt traffic and break packet capturing
Select the governance tool that is most affected by the transition to cloud
computing:
[Link] statement
[Link] reporting
[Link] of director reporting
[Link] of accounts
In terms of cloud computing and security... what is the primary governance role
of a contract?
[Link] requirements
[Link] how you extend internal controls to the cloud provider
[Link] management
[Link] define the data custodian
What is the responsibility of information risk management?
[Link] risk management to the tolerance of the data owner
[Link] overall to the organization
[Link] the overall risk of cloud providers
[Link] all risks to information assets
In which service model does the cloud consumer have to rely most on what is in
the contract and documented to enforce and manage security?
[Link]
[Link]
[Link]
[Link]
What is critical when evaluating a cloud service within your risk management
program?
[Link] the provider's security program supports your existing on-premise
tools
[Link] for the context off the information assets involved
[Link] regional harm
[Link] all outsourcing risk
How can you manage risk if you can't negotiate a contract with the cloud
provider?
[Link] compensating controls and your own risk mitigation mechanisms
[Link] choose a different provider
[Link] cyberinsurance
[Link] all potential risks
Which is not a source of compliance obligations?
[Link]
[Link] Audits
[Link]
[Link] Standards
The Cloud Security Alliance Security Guidance provides:
[Link] Guidance
[Link] you should discuss with your attorneys
[Link] Recommendation
[Link] Advice
What is the purpose of a data localization law?
[Link] require that data about the country's citizens be stored in the country
[Link] require service providers to register with the country's data protection
commission
[Link] require company to hire only local workers
[Link] require that all business documents be in the country's official language
Which CSA tool allows you to quickly search a providers assessment for
controls that map to regulations you care about and see the responses to those
controls?
[Link]
[Link]
[Link]
[Link]
The CSA Cloud Controls Matrix v3.0.1 contains how many control
specifications?
a.57
b.16
c.133
d.295
Why do cloud providers typically limit their customers' ability to directly assess
and inspect their facilities and services?
[Link] are worried customers will find vulnerabilities and they will lose
bussiness
[Link] management
[Link]-site inspections can be a security risk, and remote assessments are
hard to distinguish from real attacks
[Link] deter paying out bug bounties
A contract with a cloud service provider can fulfill all of the following except
one
[Link] what happen when the service is terminated
[Link] whether metadata can be reused for secondary purposes
[Link] the price for the service
[Link] the minimum security measures taken by the cloud provider
[Link] a breach of security
When selecting a cloud provider, if a provider won't negotiate a contract
[Link] choose another provider
[Link] the contract carefully, and consult with your advisors, to evaluate
the terms and understand the potential risks.
[Link] trust the provider
[Link] are not enforceable in cloud due to the wide range of jurisdictions
Which of the following is a standard?
[Link]
[Link]
[Link] DSS
[Link]
Which of the following cloud data storage types can be described as "a database
for files":
[Link] Storage
[Link] storage
[Link] storage
[Link] storage
Why do we use data dispersion in cloud computing?
[Link] improve sesiliency by eliminating the need for physical drives
[Link] imporve security by obviating the need for encryption
[Link] improve resiliency in case of individual drive failure
[Link] improve security by reducing the chances a complete file can be stolen
Which security tool can help detect sensitive data migrating to the cloud?
[Link] security proxies (DSP)
[Link]
[Link] Loss Prevention (DLP)
[Link]
Which of the available CASB modes is most cloud-native but often not
supported by smaller, especially SaaS, providers:
[Link]
[Link] (cloud)
[Link] (local)
[Link]-integrated
Which is the preferred model of protecting data migrating to the cloud:
[Link] proxies, because they are the most efficient
[Link] network connections, since you can't trust file encryption
[Link] files, since you can't trust network encryption
[Link] are are equally effective
How does cloud complicate access controls as compared to traditional data
storage?
[Link] is no differrence; they are not more complicated
[Link] storage may offer more options, such as sharing privileges or
access to the data's metadata
[Link] access controls are less reliable
[Link] providers must support the same access controls, which makes building
the cloud more complex
In a Cloud Computing Environment, what is always your most significant
security control?
[Link] controls
[Link] controls
[Link]-specific controls
[Link] controls
Select the 3 components of an encryption system.
[Link]
[Link] engine
[Link]
[Link]
In "externally managed" encryption, which is the key component that should be
kept externally to improve security
[Link] management
[Link]
[Link] Engine
[Link] code
Which of the following options encrypts data before you transfer it to object
storage
[Link] managed encryption
[Link] encryption
[Link]-side encryption
[Link]-side encryption
Select all potential options for encrypting data in PaaS, if they are supported by
the platform
[Link]
[Link]-level (in your own code)
[Link]-intergrated
[Link] storage
Which is the most inherently secure key management option, but it may not be
viable or even needed depending on your project requirements and
platform/provider support:
[Link] Appliance
[Link]-Party Service
[Link] Provider Service
[Link]/Appliance
Which key management option should you select if you are dealing with highly
sensitive data that you don't want your provider to potentially access under any
circumstances:
[Link] appliance
[Link]
c.3rd party key management service
[Link]/Appliance
Which option allows you to use an existing build for key management without
replicating everything in the cloud?
[Link]-party Service
[Link]
[Link] Appliance
[Link]/Appliance
For cloud, where is DLP often best integrated?
[Link] Web Gateway
[Link]
[Link] cloud virtual network/VPC
[Link]
What is the primary goal of data masking?
[Link] hackers
[Link] test data that still resembles production data
[Link] production data from employees
[Link] test data back into production data
How should the data security lifecycle be used?
[Link] create granular documentation for all sensitivi data in the cloud.
[Link] create granular documentation for all data, sensitive or not, in the cloud.
[Link] replace existing data security architectures.
[Link] a lightweight tool to better understand data flow and potential vs.
desired data usage

You might also like