Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Document preview thumbnail
Voorbeeld 1 van de 3 pagina's
Tentamen (uitwerkingen)

Cap One Project Projects-Scope Questions and Answers 100% Correct

Document preview thumbnail
Voorbeeld 1 van de 3 pagina's

Cap One Project Projects-Scope

Voorbeeld van de inhoud

Cap One Project Projects-Scope
Cloud Governance & Perimeter - answer Ensure that all internet facing AWS hosted
business applications use Barracuda WAF (and not Mod Sec)

API Authentication (Threat Detection & Vulnerability Management) - answer-Capital
One has 120+ applications running in 44+ production AWS accounts. These identified
applications have internet facing endpoints with inconsistent or missing authentication
controls.
- All APIs (SOAP / REST etc.) that are exposed externally (barring APIs that are
approved for Anonymous access as they provide data classified for Public consumption)
need to meet our API Authentication ( oAuth, Mutual SSL or Open IG / User Tokens for
public clients) and other Cyber Security standards (Transport Layer Security,
Authorization, Protected via Barracuda WAF/ AWS Shield/ Shape etc.).

IAM Role Remediation (Access Management) - answer-This initiative is to help ensure
all AWS IAM credentials used by humans and machines follow least privilege.
-Capital One has grown to 300+ AWS accounts and each account hosts applications
with varied access requirements. Access permissions (machine roles/IAM roles) were
provisioned manually prior to in-house developed Avenue tool (mid-2018) with
automated guardrails.
-Cloud engineering will be rolling out policy validations in waves. The objective is to
make sure all ASVs incorporate required changes to comply to the standards.

High-Severity Vulnerability Findings(Security Metrics and Reporting) - answerAll high
vulnerability findings are remediated within the appropriate timeframe.
• High vulnerabilities for applications are remediated within 14 days of discovery.
• High vulnerabilities for infrastructure are remediated within 60 days of discovery.
Please note that we are only currently tracking Dynamic and OSS vulnerabilities. Other
vulnerability types will be tracked in the future.

Medium Severity Vulnerability Findings (Security Metrics and Reporting) - answerAll
applications are expected to remediate their vulnerability findings reported by different
cyber scanning tools within 45 days of discovery for applications and 60 days of
discovery for infrastructure. All applicable medium severity findings (e.g. from Cyber
cyber testing categories detailed in the "Detailed Guidance" section) are in scope for
remediation.

Secrets Management (Access Management) - answer-What actions should LoBs take
for SSH Key Compliance
-Securing AWS System Accounts and Begin onboarding all BA/ASV Machine to
Machine (M2M) secrets into CoS
- Register Human Secrets in CyberArk

Documentinformatie

Geüpload op
28 mei 2025
Aantal pagina's
3
Geschreven in
2024/2025
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden
€13,73

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
julianah420
4,2
(158)
Verkocht
715
Volgers
328
Items
35956
Laatst verkocht
1 week geleden


Echte notities, van echte studenten
Elk document op Stuvia is geschreven door een medestudent die hetzelfde vak deed. Zo leer je van iemand die het al heeft gehaald.



Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen