Domain 6 - Management Plane and Business Continuity Flashcards

1
Q

The ________ is the single most significant security difference between traditional infrastructure and cloud computing. This isn’t all of the metastructure (defined in Domain 1) but is the interface to connect with the metastructure and configure much of the cloud. It is part of the metastructure and is responsible for managing the assets of the resource pool, while the cloud user is responsible for how they configure those assets, and for the assets they deploy into the cloud

A

Management Plane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True/False: The cloud user is responsible for ensuring the management plane is secure and necessary
security features are exposed to the cloud user, such as granular entitlements to control what
someone can do even if they have management plane access.

A

False. The Cloud provider is responsible for management plane security.

The cloud user is responsible for properly configuring their use of the management plane, as well as for securing and managing their credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 3 main aspects of BC/DR in the cloud?

A
  • Ensuring continuity and recovery within a given cloud provider.
  • Preparing for and managing cloud provider outages.
  • Considering options for portability, in case you need to migrate providers or platforms.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True/False: “lift and shift” wholesale migration of existing applications without architectural changes
can reduce resiliency.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True/False: The management plane is a key tool for enabling and enforcing separation and isolation in
multitenancy.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Five major facets to building and managing secure management plane

A
  • Perimeter Security
  • Customer Authentication
  • Internal Authentication and credential passing
  • Authorisation and Entitlement
  • Logging, monitoring and alerting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True/False: BC/DR is cloud provider responsibility

A

False. It is a shared responsibility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

_______ allows you to create an infrastructure template to configure all
or some aspects of a cloud deployment. These templates are then translated natively by the
cloud platform or into API calls that orchestrate the configuration.

A

Software-Defined Infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True/False: Downtime is always an option. You don’t always need perfect availability, but if you do plan
to accept an outage you should at least ensure you fail gracefully, with emergency downtime
notification pages and responses (e.g. DNS Redirection)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True/False: SaaS may often be the biggest provider outage concern, due to total reliance on the provider.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True/False: For Private cloud and privders, BC is completely on the provider’s shoulders, and BC/DR includes everything down to the physical
facilities. RTOs and RPOs will be stringent, since if the cloud goes down, everything goes down.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly