Cloud Computing Flashcards

1
Q

Describe Infrastructure as a Service (IaaS)

A

Provides virtualized computing resources
Third party hosts the servers with hypervisor running the VMs as guests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Provide 2 examples of IaaS

A

AWS, Microsoft Azure, Google Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe Platform as a Service (Paas)

A

Geared towards software development
Hardware and software hosted by provider
Provides ability to develop without having to worry about hardware or software
e.g: Heroku, SalesForce

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Provide 2 examples of PaaS

A

AWS Lambda, Google App Engine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe Software as a Service (SaaS)

A

Software that is centrally hosted and managed for the end customer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe Identity-as-a-Service (IDaaS)

A

Managed authentication services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Provide 2 examples of SaaS

A

adobe photoshop, zendesk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Describe Security-as-a-Service (SECaaS)

A

Integrates security services into corporate infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Provide 3 examples of SECaaS

A

penetration testing * authentication * intrusion detection * anti-malware * security and incident management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe Container-as-a-Service (CaaS)

A

cloud-based service offering management and hosting of containers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Provide 3 examples CaaS

A

Kubernetes, Docker Swarm, and Microsoft Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Describe Function-as-a-Service (FaaS)

A

Provides a platform allowing to develop, run, and manage functionalities without any infrastructure effort.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Provide 2 examples of FaaS

A

AWS Lambda, Google Cloud Functions, Azure Functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Describe the Private cloud model of Cloud Deployment Models

A

Provisioned for exclusive use of single organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Describe the Public cloud model of Cloud Deployment Models

A

Provisioned for open use by the general public

Exists on the premises of the cloud provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe the Community cloud model of Cloud Deployment Models

A

Shared infrastructure between several organizations with shared concerns (e.g. compliance)

17
Q

Describe the Multi cloud model of Cloud Deployment Models

A

Multi-cloud is a environment where an organization leverages two or more cloud computing platforms to perform various tasks

18
Q

Name the 5 components of NIST definition of cloud computing

A

1 - On-demand self-service
2 - Broad network access
3 - Resource pooling - shared underlying
4 - Rapid elasticity - instant scalability
5 - Measured service - Metering

19
Q

What are the 3 types of cloud defined by the NIST?

A

Software as a Service (SaaS),

Platform as a Service (PaaS)

Infrastructure as a Service (IaaS)

20
Q

What is the NIST definition of Cloud Consumer?

A

User of the cloud products and services

21
Q

What is the NIST definition of Cloud Provider?

A

Delivers cloud computing based products and services

22
Q

What is the NIST definition of Cloud Auditor?

A

independent assessor of cloud services

23
Q

What is the NIST definition of Cloud Broker?

A

Manages the use, performance and delivery of cloud services

24
Q

What is the NIST definition of Cloud Carrier?

A

Provides connectivity and transport of cloud services from providers to consumers.

25
Q

Describe Trusted Computing (TC)

A

Attempts to resolve computer security problems through hardware enhancements

Roots of Trust (RoT): set of functions within TCM that are always trusted by the OS

26
Q

What is the Cloud Wrapping attack?

A

XML rewriting attack

Changes the content of the signed part without invalidating the signature

sending/replaying envelope with changed data.

27
Q

What is the Cloud Session riding?

A

CSRF in cloud

28
Q

What is the Cloud Side(effect) channel attack?

A

A side-channel attack is any attack based on the physical implementation of a system (as opposed to attacks which are based on an algorithm) which is performed via channels or mediums that are created as a side effect of the main operation of the attacked system

29
Q

Describe the Cloud Hopper attack?

A

Initiated by delivering malware through spear-phishing emails

Goal is to compromise the accounts of staff or cloud service firms to obtain confidential information

30
Q

Describe the Cloudborne attack?

A

BMCs are a third-party component designed to enable remote server management for initial provisioning, operating system reinstallation, and troubleshooting. The attacker then implants a backdoor that gives them direct access to the hardware itself

31
Q

Describe the Man-In-The-Cloud (MITC) attack

A

MITC attacks do not rely on compromising credentials and they do not require malicious code or exploits. Instead, cybercriminals infiltrate end-user machines, steal synchronization tokens directly from the computer’s registry and place them on different devices. Google Drive does not care which machine uses the token, as long as it’s authentic

32
Q

What is the Cloud security tool CloudInspect?

A

Penetration-testing as a service from Amazon Web Services for EC2 users

33
Q

What is the Cloud security tool CloudPassage Halo?

A

Automates cloud computing security and compliance controls

34
Q

What is the Cloud security tool privacy.sexy?

A

increases privacy by reducing third party cloud-based data collection
Can also be used to harden virtual machine images and OSes that are talking to cloud services