C838 -Managing Cloud Security Exam 11
Questions with 100% Correct Answers.
Eucalyptus
Open source cloud computing and IaaS platform for enabling private clouds
Apache Cloud Stack
Open source cloud computing and IaaS platform developed to help make creating, deploying,
and managing cloud services easier by providing a complete "stack" of features and components
for cloud environments
FIPS 140-2
NIST document that lists accredited and outmoded cryptosystems
NIST 800-53
Guidance document with the primary goal of ensuring that appropriate security requirements and
controls are applied to all U.S. federal government information in information management
systems
Four Steps of a Business Requirements Analysis
1. inventory of all assets (#)
2. valuation of each asset ($)
3. determination of critical paths, processes, and assets
4. clear understanding of risk appetite
Cloud Provider Defense Roles
- strong personnel controls (background checks, and continual monitoring)
- technological controls (encryption, event logging, and access control enforcement)
- physical controls
- governance mechanisms and enforcement (policies and audits)
Cloud Customer Defense Roles
, - training programs for staff and users
- contractual enforcement of policy requirements
- use of encryption and logical isolation mechanisms
- strong access control methods
Key Components of Strong Data Retention Policies
1. Retention periods
2. Applicable regulation
3. Retention formats
4. Data classification
5. Archiving and retrieval procedures
6. Monitoring, maintenance and enforcement
ITAR
International Traffic in Arms Regulations
United States regulation; prohibitions on defense-related exports; can include cryptography
systems.
EAR
Export Administration Regulations
United States regulation; prohibitions on dual-use items (technologies that could be used for both
commercial and military purposes).
The 3 Types of Database Encryption
1. File-level - encrypting the volume or folder of the database, with the encryption engine and
keys residing on the instances attached to the volume; protects from media theft, lost backups,
and external attack but does not protect against attacks with access to the application layer, the
instance's OS, or the database itself
2. Transparent - encrypting the entire database or specific portions, such as tables; encryption
engine resides within the database, and it is transparent to the application; keys usually reside
within the instance, although processing and management of them may also be offloaded to an
external KMS; provides effective protection from media theft, backup system intrusions, and
Questions with 100% Correct Answers.
Eucalyptus
Open source cloud computing and IaaS platform for enabling private clouds
Apache Cloud Stack
Open source cloud computing and IaaS platform developed to help make creating, deploying,
and managing cloud services easier by providing a complete "stack" of features and components
for cloud environments
FIPS 140-2
NIST document that lists accredited and outmoded cryptosystems
NIST 800-53
Guidance document with the primary goal of ensuring that appropriate security requirements and
controls are applied to all U.S. federal government information in information management
systems
Four Steps of a Business Requirements Analysis
1. inventory of all assets (#)
2. valuation of each asset ($)
3. determination of critical paths, processes, and assets
4. clear understanding of risk appetite
Cloud Provider Defense Roles
- strong personnel controls (background checks, and continual monitoring)
- technological controls (encryption, event logging, and access control enforcement)
- physical controls
- governance mechanisms and enforcement (policies and audits)
Cloud Customer Defense Roles
, - training programs for staff and users
- contractual enforcement of policy requirements
- use of encryption and logical isolation mechanisms
- strong access control methods
Key Components of Strong Data Retention Policies
1. Retention periods
2. Applicable regulation
3. Retention formats
4. Data classification
5. Archiving and retrieval procedures
6. Monitoring, maintenance and enforcement
ITAR
International Traffic in Arms Regulations
United States regulation; prohibitions on defense-related exports; can include cryptography
systems.
EAR
Export Administration Regulations
United States regulation; prohibitions on dual-use items (technologies that could be used for both
commercial and military purposes).
The 3 Types of Database Encryption
1. File-level - encrypting the volume or folder of the database, with the encryption engine and
keys residing on the instances attached to the volume; protects from media theft, lost backups,
and external attack but does not protect against attacks with access to the application layer, the
instance's OS, or the database itself
2. Transparent - encrypting the entire database or specific portions, such as tables; encryption
engine resides within the database, and it is transparent to the application; keys usually reside
within the instance, although processing and management of them may also be offloaded to an
external KMS; provides effective protection from media theft, backup system intrusions, and