C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
1. _____ drive security decisions. business requirements
2. All of these are reasons because of which an organi- Elimination of risks
zation may want to consider cloud migration, except:
3. The generally accepted definition of cloud computing negating the need for
includes all of the following characteristics except: backups
4. When a cloud customer uploads PII to a cloud cloud customer
provider, who becomes ultimately responsible for the
security of that PII?
5. We use which of the following to determine the critical BIA
paths, processes, and assets of an organization?
6. If a service or solution does not meet all of the spec- On-demand self-service
ified key characteristics listed below, it is said to be Broad network access
not true cloud computing. Please select the valid cloud Resource pooling
computing characteristics out of the terms identified measured service
below.
Each correct answer represents a complete solution.
Choose all that apply.
7. All of these technologies have made cloud service smart hubs
viable except:
8. The cloud deployment model that features organiza- private
tional ownership of the hardware and infrastructure,
and usage only by members of that organization, is
known as:
9. Public
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
The cloud deployment model that features ownership
by a cloud provider, with services offered to anyone
who wants to subscribe, is known as:
10. The cloud deployment model that features joint own- Community
ership of assets among an affinity group is known as:
11. If a cloud customer wants a secure, isolated sand- PaaS
box in order to conduct software development and
testing, which cloud service model would probably be
best?
12. If a cloud customer wants a fully-operational environ- SaaS
ment with very little maintenance or administration
necessary, which cloud service model would probably
be best?
13. If a cloud customer wants a bare-bones environment IaaS
in which to replicate their own enterprise for BC/DR
purposes, which cloud service model would probably
be best?
14. Which of the following is not a common cloud service Programming as a Service
model?
15. Cloud Access Security Brokers (CASBs) might offer all BC / DR / COOP
the following services EXCEPT:
16. If a cloud customer cannot get access to the cloud Availability
provider, this affects what portion of the CIA triad?
17. All of the following can result in vendor lock-in except: Statutory compliance
18. vendor lock-out
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
The risk that a cloud provider might go out of business
and the cloud customer might not be able to recover
data is known as:
19. All of these are features of cloud computing except: Reversed charging config-
uration
20. Cloud vendors are held to contractual obligations with SLAs
specified metrics by:
21. Gathering business requirements can aid the orga- Usefulness
nization in determining all of this information about
organizational assets, except:
22. The BIA can be used to provide information about all Secure Acquisition
of the following, except:
23. Risk appetite for an organization is determined by Senior management
which of the following?
24. What is the risk left over after controls and counter- Residual
measures are put in place?
25. All the following are ways of addressing risk, except: Reversal
26. Which of the following best describes risk? The likelihood that a threat
will exploit a vulnerability
27. In which cloud service model is the customer required IaaS
to maintain the OS?
28. In which cloud service model is the customer required PaaS
to maintain and update only the applications?
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
29. In which cloud service model is the customer only SaaS
responsible for the data?
30. The cloud customer and provider negotiate their re- Contract
spective responsibilities and rights regarding the ca-
pabilities and data of the cloud service. Where is the
eventual agreement codified?
31. In attempting to provide a layered defense, the secu- All of These
rity practitioner should convince senior management (Technological, Physical,
to include security controls of which type? Administrative)
32. Which of the following is considered an administrative Access control process
control?
33. Which of the following is considered a technological Firewall Software
control?
34. Which of the following is considered a physical con- Fences
trol?
35. In a cloud environment, encryption should be used for Profile formatting
all the following, except:
36. The process of hardening a device should include all Improve default accounts
of the following, except:
37. The process of hardening a device should include updating and patching
which of the following? the system
38. What is an experimental technology that is intended Homomorphic
to create the possibility of processing encrypted data
without having to decrypt it first?
Study online at https://quizlet.com/_8g2ipe
1. _____ drive security decisions. business requirements
2. All of these are reasons because of which an organi- Elimination of risks
zation may want to consider cloud migration, except:
3. The generally accepted definition of cloud computing negating the need for
includes all of the following characteristics except: backups
4. When a cloud customer uploads PII to a cloud cloud customer
provider, who becomes ultimately responsible for the
security of that PII?
5. We use which of the following to determine the critical BIA
paths, processes, and assets of an organization?
6. If a service or solution does not meet all of the spec- On-demand self-service
ified key characteristics listed below, it is said to be Broad network access
not true cloud computing. Please select the valid cloud Resource pooling
computing characteristics out of the terms identified measured service
below.
Each correct answer represents a complete solution.
Choose all that apply.
7. All of these technologies have made cloud service smart hubs
viable except:
8. The cloud deployment model that features organiza- private
tional ownership of the hardware and infrastructure,
and usage only by members of that organization, is
known as:
9. Public
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
The cloud deployment model that features ownership
by a cloud provider, with services offered to anyone
who wants to subscribe, is known as:
10. The cloud deployment model that features joint own- Community
ership of assets among an affinity group is known as:
11. If a cloud customer wants a secure, isolated sand- PaaS
box in order to conduct software development and
testing, which cloud service model would probably be
best?
12. If a cloud customer wants a fully-operational environ- SaaS
ment with very little maintenance or administration
necessary, which cloud service model would probably
be best?
13. If a cloud customer wants a bare-bones environment IaaS
in which to replicate their own enterprise for BC/DR
purposes, which cloud service model would probably
be best?
14. Which of the following is not a common cloud service Programming as a Service
model?
15. Cloud Access Security Brokers (CASBs) might offer all BC / DR / COOP
the following services EXCEPT:
16. If a cloud customer cannot get access to the cloud Availability
provider, this affects what portion of the CIA triad?
17. All of the following can result in vendor lock-in except: Statutory compliance
18. vendor lock-out
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
The risk that a cloud provider might go out of business
and the cloud customer might not be able to recover
data is known as:
19. All of these are features of cloud computing except: Reversed charging config-
uration
20. Cloud vendors are held to contractual obligations with SLAs
specified metrics by:
21. Gathering business requirements can aid the orga- Usefulness
nization in determining all of this information about
organizational assets, except:
22. The BIA can be used to provide information about all Secure Acquisition
of the following, except:
23. Risk appetite for an organization is determined by Senior management
which of the following?
24. What is the risk left over after controls and counter- Residual
measures are put in place?
25. All the following are ways of addressing risk, except: Reversal
26. Which of the following best describes risk? The likelihood that a threat
will exploit a vulnerability
27. In which cloud service model is the customer required IaaS
to maintain the OS?
28. In which cloud service model is the customer required PaaS
to maintain and update only the applications?
, C838 - Managing Cloud Security
Study online at https://quizlet.com/_8g2ipe
29. In which cloud service model is the customer only SaaS
responsible for the data?
30. The cloud customer and provider negotiate their re- Contract
spective responsibilities and rights regarding the ca-
pabilities and data of the cloud service. Where is the
eventual agreement codified?
31. In attempting to provide a layered defense, the secu- All of These
rity practitioner should convince senior management (Technological, Physical,
to include security controls of which type? Administrative)
32. Which of the following is considered an administrative Access control process
control?
33. Which of the following is considered a technological Firewall Software
control?
34. Which of the following is considered a physical con- Fences
trol?
35. In a cloud environment, encryption should be used for Profile formatting
all the following, except:
36. The process of hardening a device should include all Improve default accounts
of the following, except:
37. The process of hardening a device should include updating and patching
which of the following? the system
38. What is an experimental technology that is intended Homomorphic
to create the possibility of processing encrypted data
without having to decrypt it first?