Chapter 5: Domain 5: Cloud Security Operations (Ben Malisow) Flashcards
What is the primary incident response goal?
A. Remediating the incident
B. Reverting to the last known good state
C. Determining the scope of the possible loss
D. Outcomes dictated by business requirements
D. Outcomes dictated by business requirements
Explanation:
This is not an easy question; different industries and different organizations will have differing goals. Each organization will determine for itself what the primary goal of incident response will be, and this may even differ from incident to incident, depending on the nature of the incident itself (in other words, a given organization may set priorities such that the primary goal of incident response in a disaster is continuity of operations, while the goal in responding to unauthorized access may be halting data disclosure).
You are in charge of building a cloud data center.
Which raised floor level is sufficient to meet standard requirements?
A. 10 inches
B. 8 inches
C. 18 inches
D. 2 feet
D. 2 feet
Explanation:
The minimum recommended height of a raised floor in a data center is 24 inches. All other options are incorrect.
You are in charge of building a cloud data center. What purposes does the raised floor serve?
A. Allows airflow and increases structural soundness for holding large components
B. Cold air feed and a place to run wires for the machines
C. Additional storage for critical components and a dedicated access to a landline
D. Fire suppression systems and personnel safety
B. Cold air feed and a place to run wires for the machines
Explanation:
The raised floor in a data center will serve as an air plenum (usually for cold air) and a wiring chase. All the other options are incorrect.
You are in charge of building a cloud data center. Which of the following is a useful rack configuration for regulating airflow?
A. Exhaust fans on racks facing the inlet vents of other racks
B. Inlet fans on racks facing exhaust fans of other racks
C. All racks perpendicular to each other
D. Exhaust fans on racks facing exhaust fans on other racks
D. Exhaust fans on racks facing exhaust fans on other racks
Explanation:
The preferred method is cold aisle containment (hot aisle containment, where the inlets on racks face each other, is all right too). Options A and B are the same incorrect answer, just worded differently; if the exhaust fans on one rack face into the inlet vents on another rack, you would end up blowing warm air into the components, defeating the purpose of airflow management.
Perpendicular racks will not optimize your airflow
An event is something that can be measured within the environment. An incident is a(n) _______________ event.
A. Deleterious
B. Negative
C. Unscheduled
D. Major
C. Unscheduled
Explanation:
All activity in the environment can be considered events. Any event that was not planned or known is an incident. In the security industry, we often ascribe negative effects to the term incident, but incidents are not always malicious; they are only unscheduled. All the other options are incorrect.
Which of the following factors would probably most affect the design of a cloud data center?
A. Geographic location
B. Functional purpose
C. Cost
D. Aesthetic intent
A. Geographic location
Explanation:
This is a difficult, nuanced question. Options A–C are true; each element would affect the design of a cloud data center (D is not something that should be included in data center design). But the physical location of the data center would include legal constraints (based on jurisdiction), geological/natural constraints (based on altitude, proximity to water formations/flooding, climate, natural disaster, etc.), price, and other variables. Therefore, location would most likely have the greatest impact on the design of the facility.
All of the following elements must be considered in the design of a cloud data center except _______________.
A. External standards, such as ITIL or ISO 27001
B. Physical environment
C. Types of services offered
D. Native language of the majority of customers
D. Native language of the majority of customers
Explanation:
Language of the customers is irrelevant, assuming they can pay. All the other options are factors that must be considered in data center design.
In designing a data center to meet their own needs and provide optimum revenue/profit, the cloud provider will most likely aim to enhance _______________.
A. Functionality
B. Automation of services
C. Aesthetic value
D. Inherent value
B. Automation of services
Explanation:
This is not an easy question. All the options are correct except C. Option B is the most correct because it will lead to maximizing performance, value, and profitability.
You are the security officer for a small cloud provider offering public cloud infrastructure as a service (IaaS); your clients are predominantly from the education sector, located in North America. Of the following technology architecture traits, which is probably the one your organization would most likely want to focus on?
A. Reducing mean time to repair (MTTR)
B. Reducing mean time between failure (MTBF)
C. Reducing the recovery time objective (RTO)
D. Automating service enablement
D. Automating service enablement
Explanation:
The goal of automating service enablement is probably paramount for any cloud service provider (of the qualities listed), because it allows for the most scalability and offers the most significant reduction in costs (which mainly come from personnel) and therefore the most profitability. The details of “public cloud,” “IaaS,” and “North America” are distractors in this context as they are irrelevant—this answer would be true for any cloud provider offering any type of services. Options A and B are not true because most cloud providers of any appreciable size are purchasing hardware on a scale that makes the per-unit failure rate fairly irrelevant; the bulk nature of IT purchases by cloud providers makes differences in MTTR and MTBF between vendors and products statistically insignificant. Option C is incorrect because RTO is a quality involving business continuity and disaster recovery (BC/DR) planning, not IT architecture.
What is perhaps the main way in which software-defined networking (SDN) solutions facilitate security in the cloud environment?
A. Monitoring outbound traffic
B. Monitoring inbound traffic
C. Segmenting networks
D. Preventing distributed denial of service (DDoS) attacks
C. Segmenting networks
Explanation:
Network segmentation allows providers to create zones of trust within the cloud environment, tailoring the available services to meet the needs of a variety of clients and markets. SDN does not really involve monitoring outbound traffic (that is done by egress monitoring solutions) or inbound traffic (that is usually performed by firewalls and routers), nor does it really prevent DDoS attacks (nothing can prevent such attacks, and risk reduction is usually done by routers), so all the other options are incorrect.
The logical design of a cloud environment can enhance the security offered in that environment. For instance, in a software as a service (SaaS) cloud, the provider can incorporate _______________ capabilities into the application itself.
A. High-speed processing
B. Logging
C. Performance-enhancing
D. Cross-platform functionality
B. Logging
Explanation:
The ability to log activity is useful for many security purposes (such as monitoring and forensics); having that purposefully included in SaaS applications reduces the need to have a different tool added to the environment to achieve that same goal and reduces the possibility that any additional interface won’t perform optimally. The other options are all about enhancing the customer’s ability to perform business function or meeting the customer’s business needs. Although this is paramount from the customer’s perspective and may tangentially fulfill some security purpose (increased processing capacity may, for instance, allow the use of additional encryption, where the overhead may otherwise deter the use of that tool), these are not direct security purposes and therefore are not correct answers to this specific question.
You are tasked with managing a cloud data center in Los Angeles; your customers are mostly from the entertainment industry, and you are offering both platform as a service (PaaS) and software as a service (SaaS) capabilities. From a physical design standpoint, you are probably going to be most concerned with _______________.
A. Offering digital rights management (DRM) capabilities
B. Insuring against seasonal floods
C. Preventing all malware infection potential
D. Ensuring that the racks and utilities can endure an earthquake
D. Ensuring that the racks and utilities can endure an earthquake
Explanation:
California is known for suffering massive destruction from earthquakes, and physical design is the means with which this risk is addressed. All the other options either involve a nonphysical risk (DRM will be necessary, because the entertainment industry relies heavily on copyrighted material) or a method other than physical design to address a risk (floods are physical threats, but insurance is an administrative control for risk transfer), so D is the best choice of these options.
You are the security manager for a small retail business involved mainly in direct e-commerce transactions with individual customers (members of the public). The bulk of your market is in Asia, but you do fulfill orders globally. Your company has its own data center located within its headquarters building in Hong Kong, but it also uses a public cloud environment for contingency backup and archiving purposes. Your cloud provider is changing its business model at the end of your contract term, and you have to find a new provider. In choosing providers, which tier of the Uptime Institute rating system should you be looking for, if minimizing cost is your ultimate goal?
A. 1
B. 3
C. 4
D. 8
A. 1
Explanation:
For the purposes described in the question, a Tier 1 data center should suffice; it is the cheapest, and you need it only for occasional backup purposes (as opposed to constant access). The details of location and market are irrelevant. Tiers 3 and 4 would be much more expensive, and they are not necessary for your business purposes; options B and C are thus incorrect. There is no Tier 8 in the Uptime Institute system.
You are the security manager for a small retail business involved mainly in direct e-commerce transactions with individual customers (members of the public). The bulk of your market is in Asia, but you do fulfill orders globally. Your company has its own data center located within its headquarters building in Hong Kong, but it also uses a public cloud environment for contingency backup and archiving purposes. Your cloud provider is changing its business model at the end of your contract term, and you have to find a new provider. In choosing providers, which of the following functionalities will you consider absolutely essential?
A. Distributed denial of service (DDoS) protections
B. Constant data mirroring
C. Encryption
D. Hashing
C. Encryption
Explanation:
If your company is involved in e-commerce, you are most likely using credit cards for online transactions; if you’re using credit cards, you are almost certainly constrained by the Payment Card Industry Data Security Standard (PCI DSS) or one of the other contractual standards like it. Because of this, you will be required to encrypt or tokenize all stored cardholder data, and for long-term storage, encryption is the cheaper, more durable process. DDoS and mirroring are availability protections, and availability is not your company’s main concern for cloud services from the question description; long-term storage is not focused on availability. Options A and B are thus incorrect. Hashing is an integrity protection, and though hashes may be useful in this case (to determine whether stored data is accurate), they won’t be as important as compliance with credit card standards. Option C is the preferable answer compared to D.
You are the security manager for a small retail business involved mainly in direct e-commerce transactions with individual customers (members of the public). The bulk of your market is in Asia, but you do fulfill orders globally. Your company has its own data center located within its headquarters building in Hong Kong, but it also uses a public cloud environment for contingency backup and archiving purposes. Which of the following standards are you most likely to adopt?
A. National Institute of Standards and Technology (NIST) 800-37
B. General Data Protection Regulation (GDPR)
C. ISO 27001
D. Sarbanes–Oxley Act (SOX)
C. ISO 27001
Explanation:
ISO is the only truly international standard on this list of choices; all the rest are either American laws or standards (options A and D) or European (option B).
You are the security manager for a small retail business involved mainly in direct e-commerce transactions with individual customers (members of the public). The bulk of your market is in Asia, but you do fulfill orders globally. Your company has its own data center located within its headquarters building in Hong Kong, but it also uses a public cloud environment for contingency backup and archiving purposes. Your company has decided to expand its business to include selling and monitoring life-support equipment for medical providers. What characteristic do you need to ensure is offered by your cloud provider?
A. Full automation of security controls within the cloud data center
B. Tier 4 of the Uptime Institute certifications
C. Global remote access
D. Prevention of ransomware infections
B. Tier 4 of the Uptime Institute certifications
Explanation:
The changing nature of your business will require a much more stringent set of operating standards, to include an increase in Uptime Institute tier levels; because you’re no longer just using the cloud for backup and long-term storage and are now using it in direct support of health and human safety, Tier 4 is required. Fully automated security controls are useful from the provider’s perspective (allowing more profitability and scalability), but this is not a major concern of the customer. Option A is incorrect.
Global remote access and reducing the risk of malware infections (to include ransomware) are basic functions of almost all cloud providers; these functions aren’t useful discriminators when choosing cloud providers because all cloud providers have them. Options C and D are thus incorrect.
When designing a cloud data center, which of the following aspects is not necessary to ensure continuity of operations during contingency operations?
A. Access to clean water
B. Broadband data connection
C. Extended battery backup
D.Physical access to the data center
C. Extended battery backup
Explanation:
Backup power does not have to be delivered by batteries; it can be fed to the data center through redundant utility lines or from a generator. All the other elements are necessary for safe and secure data center operations, for both the personnel and the equipment within the data center.
You are the security manager for a small surgical center. Your organization is reviewing upgrade options for its current, on-premises data center. In order to best meet your needs, which one of the following options would you recommend to senior management?
A. Building a completely new data center
B. Leasing a data center that is currently owned by another firm
C. Renting private cloud space in a Tier 2 data center
D.Staying with the current data center
A. Building a completely new data center
Explanation:
This answer is mostly arrived at through a process of elimination. Option B is not optimum because of the potential for vendor lock-in, restrictions on buildout, and privacy concerns. Option C is not optimum because Tier 2 is not sufficient for medical uses.
Option D is not optimum because there was obviously a reason to consider a new option. We are therefore left with option A, which is the most expensive of the choices but allows the greatest amount of control and security.
When building a new data center within an urban environment, which of the following is probably the most restrictive aspect?
A.The size of the plot
B. Utility availability
C. Staffing
D. Municipal codes
D. Municipal codes
Explanation:
In any large metropolitan area, government restrictions on development and construction can severely limit how you use your property; this can be a significant limiting factor in building a data center. The size of the plot may or may not matter, depending on if you are allowed to build up or dig down to make use of additional space—these options will be limited by municipal building codes, so option D is preferable to option A. Utilities and personnel are usually easy to acquire in an urban setting, so options B and C are incorrect.
When you are building a new data center in a rural setting, which of the following is probably the most restrictive aspect?
A. Natural disasters
B. Staffing
C. Availability of emergency services
D. Municipal Codes
C. Availability of emergency services
Explanation:
In a rural location, the positioning and depth of first responders (fire, law enforcement, paramedics, etc.) may be severely limited in comparison to an urban setting.
Natural disasters affect all locations, rural or urban, so a rural setting is not any more or less limiting in planning accordingly; option A is incorrect. Oddly enough, because of the very limited need for personnel within modern data centers with significant automation, recruiting and placing the number of people necessary to serve the purpose should not be too difficult; option B is not correct. One of the appeals of a rural setting is that building codes are often rudimentary or nonexistent. Option D is incorrect.
All tiers of the Uptime Institute standards for data centers require _______________ hours of on-site generator fuel.
A. 6
B. 10
C. 12
D. 15
C. 12
Explanation:
All the other options are incorrect
The American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) guidelines for internal environmental conditions within a data center suggest that a temperature setting of _______________ degrees (F) would be too high.
A. 93
B. 80
C. 72
D. 32
A. 93
Explanation:
The range suggested by the ASHRAE Technical Committee 9.9 is 64 to 81 degrees Fahrenheit. All the other options are distractors (although D is particularly distracting, because it is lower than the recommended range, but that is not what the question is asking).
Internal data center conditions that exceed the American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) guidelines for humidity could lead to an increase of the potential for all of the following except _______________.
A. Biological intrusion
B. Electrical shorting
C. Corrosion/oxidation
D. Social engineering
D. Social engineering
Explanation:
Being damp does not make people more susceptible to trickery.
Moisture in the air can, however, create mold/mildew, short circuits, and rust, so all the other options are incorrect.
Setting thermostat controls by measuring the _______________ temperature will result in the highest energy costs.
A. Server inlet
B. Return air
C. Under-floor
D. External ambient
B. Return air
Explanation:
The return air temperature will be slightly higher than anywhere else inside the data center because the air has been warmed by passing through the equipment (thus cooling the equipment but warming the air). Using this as a temperature set point will result in much cooler air feeding the server inlets, which takes more energy, which will be more expensive. Options A and C are incorrect because that air is already cold; using these locations as set points will not consume as much energy and may result in somewhat warmer air entering the servers. This will be less expensive than option B. Option D is an outlying distractor; if you set your heating, ventilation, and air conditioning (HVAC) controls to respond to the temperature outside the data center, your HVAC units are responding to temperatures that have nothing to do with the internal environment. In effect, you’d be trying to adjust the temperature of the outside world, which is ridiculous.