Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 31 páginas
Examen

WGU D320 - MANAGING CLOUD SECURITY VERSION (JYO2) QUESTIONS AND ANSWERS 2024

Document preview thumbnail
Vista previa 4 fuera de 31 páginas

WGU D320 - MANAGING CLOUD SECURITY VERSION (JYO2) QUESTIONS AND ANSWERS 2024

Vista previa del contenido

WGU D320 - MANAGING CLOUD SECURITY
VERSION (JYO2)
SOC 1

SOC Report type: strictly for auditing the financial reporting instruments of a
corporation

SOC 2

SOC Report type: Intended to report audits of any controls on an organization's
security, availability, processing integrity, confidentiality, and privacy.

SOC 3

SOC Report type: Designed to be shared with the public.

Seal of approval. Does not contain any actual data about the security controls of
the audit target.

encrypted

Data at rest should be _________.

Defining

SDLC Phase focused on identifying the business requirements of the application,
such as accounting, database, or customer relationship management

Designing

SDLC Phase: Begin to develop user stories (what the user will want to accomplish,
what interface will look like and whether it will require the use or development of
any APIs)

Development

SDLC Phase where the code is written.

,Testing

SDLC Phase where activities such as initial pen testing and vulnerability scanning
against the application are performed. Will use both dynamic and static testing or
DSAT (Dynamic Application Security Testing) or SAST (Static Application Security
Testing).

Secure Operations

SDLC Phase where after testing, the application is deemed secure.

Disposal

SDLC Phase where app has reached end of life or has been replaced with a newer
or different application.

S (Spoofing)

T (Tampering)

R (Repudiation)

I (Information Disclosure)

D (Denial of Service)

E (Elevation of Privilege)

STRIDE

Graham-Leach-Bliley Act (GLBA)

Allow banks to merge with and own insurance companies. Included in the law
were stipulations that customer account information be kept secure and private,
and that customers be allowed to opt out of any information-sharing
arrangements the bank or insurer might engage in.

Sarbanes-Oxley Act (SOX)

,Law that increases transparency into publicly traded corporations' financial
activities.

HIPPA

Law that protects patient records and data.

FERPA

Law that prevents academic institutions from sharing student data with anyone
other than parents or students (after age 18)

DMCA

provisions to protect owned data; cracking of access controls on copyrighted
media a crime and enables holders to require any site to remove content

CLOUD Act

Allows US law enforcement and courts to compel American companies to disclose
data stored in foreign data centers.

GDPR

Most significant, powerful personal privacy law in the world. Describes the
appropriate handling of personal and private information of all EU citizens.

Crypto-shredding

The practice of 'deleting' data by deliberately deleting or overwriting the
encryption keys.



Business Impact Analysis (BIA)

A process that assesses and identifies the potential effects of disruptions to a
business operation.

SPOF

, A component or system that, if it fails, will cause the entire system to fail.

Quantitative

Risk assessment that uses specific numerical values

Qualitative

Risk assessment that uses non-numerical categories that are relative in nature,
such as high, medium, and low.

Risk appetite

level, amount, or type of risk that the organization finds acceptable

Residual risk

The remaining risk that exists after countermeasures have been applied.

IaaS

Service model where cloud customer has the most responsibility and authority.
Cloud provider is only liable for the underlying hardware.

PaaS

Service model where cloud customer loses more control because the cloud
provider is responsible for installing, maintaining, and administering the OS as
well as underlying hardware.

SaaS

Service model where cloud customer loses all control of the environment. Cloud
provider is responsible for all of the underlying hardware and software.

Homomorphic encryption

A method of processing data in the cloud while it remains encrypted.

Defense in depth

Información del documento

Subido en
11 de septiembre de 2024
Número de páginas
31
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$13.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Teacher101
4.6
(277)
Vendido
522
Seguidores
74
Artículos
11506
Última venta
3 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes