C838 – Opening Exam Questions with
100% Correct Answers.
Private Cloud
resources dedicated to a single customer; might be owned and maintained by the entity that is
the sole customer (org might own and operate a data center that serves as the cloud environment
for the org's users); might be a set of resources (racks, blades, software packages) owned by the
single customer but located and maintained at provider's data center; provider might offer
physical security, admin services, and utilities (power, Internet) for customers (referred to as co-
lo (co-located) environment)
Community Cloud
,features infrastructure and processing owned and operated by/for an affinity group; orgs come
together to perform joint tasks and functions; gaming communities, ownership is spread
throughout the various members of the community; can be provisioned by a third party
(FedRAMP service - only used by US federal gov)
Hybrid Cloud
contains elements of other models; org might want to retain some private cloud resources
(remote user access) but lease some public cloud space (PaaS function for software
development/testing)
Cloud Broker
company that purchases hosting services from a provider and resells them to its own customers
CASB (Cloud Access Security Broker)
third-party entity offering independent IAM (identity and access management) services to
CSPs and cloud customers; can be SSO, certificate management, and cryptographic key escrow
Regulators
ensure orgs are incompliance with regulatory framework for which they are responsible
for; HIPAA, GLBA, PCI DSS, ISO, SOX, etc.; regulators include FTC, SEC, and auditors
Cost-Benefit Analysis
comparing potential positive impact (profit, efficiency, market share) of a business decision
to potential negative impact (expense, detriment to production, risk) and weighing the two as
equivalent or not (potential positive/negative)
FIPS 140-2
NIST document that describes the process for accrediting and cryptosystems for use by
the federal government; lists only approved cryptographic tools
NIST 800-53
guidance document with primary goal of ensuring appropriate security requirements and
controls are applied to all US federal government information in management systems
, TCI (Trusted Cloud Initiative) Reference Model
guide for cloud providers, allowing them to create a holistic architecture that customers can
purchase (including physical/logical layout of network and processes necessary to utilize both)
Vendor Lock-In
situation where a customer is unable to leave, migrate, retrieve, or transfer data to an alternate
provider due to technical/nontechnical constraints; use portability for a level of ease when
transporting data, ensure contract states so, avoid proprietary formats (requires specific software to
read data), check for regulatory constraints; detrimental contract terms or technical limitations
Vendor Lock-Out
when a customer is unable to recover/access their own data due to provider going
into bankruptcy or leaving the market
Blockchain
open means of conveying value using encryption technologies/algorithms (cryptocurrency);
transactional ledger where all participants can view every transaction, making it extremely
difficult to negatively affect the integrity of past transactions; each record (block) is
distributed among all participants in a distributed or cloud-based manner
Containers
logical segmentation of memory space in a device, creating two or more abstract areas
that cannot interface directly; commonly used in BYOD environment; distinguish two
distinct partitions (one for work functions/data and other for personal functions/data)
Quantum Computing
emerging technology that allow IT systems to operate beyond binary math; instead of using
the presence of electrons for calculations (electrons is either present/not present), quantum
computing may use subatomic characteristics (electron spin, charm, etc.) to offer computing
on exponentially larger scale
Homomorphic Encryption
100% Correct Answers.
Private Cloud
resources dedicated to a single customer; might be owned and maintained by the entity that is
the sole customer (org might own and operate a data center that serves as the cloud environment
for the org's users); might be a set of resources (racks, blades, software packages) owned by the
single customer but located and maintained at provider's data center; provider might offer
physical security, admin services, and utilities (power, Internet) for customers (referred to as co-
lo (co-located) environment)
Community Cloud
,features infrastructure and processing owned and operated by/for an affinity group; orgs come
together to perform joint tasks and functions; gaming communities, ownership is spread
throughout the various members of the community; can be provisioned by a third party
(FedRAMP service - only used by US federal gov)
Hybrid Cloud
contains elements of other models; org might want to retain some private cloud resources
(remote user access) but lease some public cloud space (PaaS function for software
development/testing)
Cloud Broker
company that purchases hosting services from a provider and resells them to its own customers
CASB (Cloud Access Security Broker)
third-party entity offering independent IAM (identity and access management) services to
CSPs and cloud customers; can be SSO, certificate management, and cryptographic key escrow
Regulators
ensure orgs are incompliance with regulatory framework for which they are responsible
for; HIPAA, GLBA, PCI DSS, ISO, SOX, etc.; regulators include FTC, SEC, and auditors
Cost-Benefit Analysis
comparing potential positive impact (profit, efficiency, market share) of a business decision
to potential negative impact (expense, detriment to production, risk) and weighing the two as
equivalent or not (potential positive/negative)
FIPS 140-2
NIST document that describes the process for accrediting and cryptosystems for use by
the federal government; lists only approved cryptographic tools
NIST 800-53
guidance document with primary goal of ensuring appropriate security requirements and
controls are applied to all US federal government information in management systems
, TCI (Trusted Cloud Initiative) Reference Model
guide for cloud providers, allowing them to create a holistic architecture that customers can
purchase (including physical/logical layout of network and processes necessary to utilize both)
Vendor Lock-In
situation where a customer is unable to leave, migrate, retrieve, or transfer data to an alternate
provider due to technical/nontechnical constraints; use portability for a level of ease when
transporting data, ensure contract states so, avoid proprietary formats (requires specific software to
read data), check for regulatory constraints; detrimental contract terms or technical limitations
Vendor Lock-Out
when a customer is unable to recover/access their own data due to provider going
into bankruptcy or leaving the market
Blockchain
open means of conveying value using encryption technologies/algorithms (cryptocurrency);
transactional ledger where all participants can view every transaction, making it extremely
difficult to negatively affect the integrity of past transactions; each record (block) is
distributed among all participants in a distributed or cloud-based manner
Containers
logical segmentation of memory space in a device, creating two or more abstract areas
that cannot interface directly; commonly used in BYOD environment; distinguish two
distinct partitions (one for work functions/data and other for personal functions/data)
Quantum Computing
emerging technology that allow IT systems to operate beyond binary math; instead of using
the presence of electrons for calculations (electrons is either present/not present), quantum
computing may use subatomic characteristics (electron spin, charm, etc.) to offer computing
on exponentially larger scale
Homomorphic Encryption