GCGA Ch. 5 Summarizing Cloud Concepts (ST) Flashcards
(15 cards)
Cloud computing
provides an organization with additional resources. Most cloud services are provided via the Internet or a hosting provider. On-premise clouds are owned and maintained by an organization.
SaaS
Software as a Service (SaaS) includes web-based applications such as web-based email.
PaaS
Platform as a Service (PaaS) provides an easy-to-configure operating system and on-demand computing for customers. The vendor keeps systems up to date with current patches.
IaaS
Infrastructure as a Service (IaaS) provides hardware resources via the cloud. It can help an organization limit the size of its hardware footprint and reduce personnel costs.
MSP
A managed service provider (MSP) is a third-party vendor that provides any IT services needed by an organization, including security services. A managed security service provider (MSSP) focuses on providing security services for an organization.
CASB
A cloud access security broker (CASB) is a software tool or service deployed between an organization’s network and the cloud provider. It monitors all network traffic and can enforce security policies.
Private clouds
designed for use by a single organization.
Third-party cloud vendors
sell access to public cloud services to anyone who wants them.
Community clouds
Two or more organizations with shared concerns can share a community cloud.
Hybrid cloud
A hybrid cloud is a combination of two or more cloud deployment models. Multi-cloud systems combine the resources from two or more cloud service providers. Cloud-based DLP systems can enforce security policies for any data stored in the cloud.
Next-generation secure web gateway
provides proxy services for traffic from clients to Internet sites. It can filter URLs and scan for malware.
Common cloud security considerations
include availability, resilience, cost, responsiveness, scalability, and segmentation.
On-premises vs off-premises deployments
may be created using a centralized approach, with a small number of physical locations, or a decentralized approach, with many physical locations. Off-premises solutions make use of cloud service providers.
IaC
Infrastructure as code (IaC) refers to managing and provisioning data centers with code to define VMs and virtual networks.
SDN
Software-defined networks (SDN) use virtualization technologies to route traffic instead of using hardware routers and switches.