Learnzapp Flashcards
Maintenance mode
Generation of new instances is prevented.
Alerting mechanisms are suspended.
Events are logged.
Admin access continues
Remember EU member states
Maintenance mode :
Live migration
snapshots
Live migration is the term used to describe the movement of functioning virtual instances from one physical host to another and how VMs are moved prior to maintenance on a physical device.
VMs are moved as image snapshots when they are transitioned from production to storage;
During live migration, the VM moves in unencrypted form.
Live migration goes over the network; portable media is not necessary.
Tunneling
Generic routing encapsulation (GRE) is a tunneling mechanism, specifically designed for the purpose.
SSH tunnelling includes the services
Remote login
Port forwarding
Command Execution
TLS
TLS is a session encryption tool that uses asymmetric encryption to create a symmetric session key
which risk can make - cloud env unviable
VM Sprawl
NAS ( Network attached Storage)
SAN (Storage Area Network)
NAS: file server that provides data access to multiple, heterogeneous machines and users on the network
NAS is designed basically for file sharing across the network.
SAN :A SAN typically presents storage devices to users as attached/mounted drives.
SAN is designed to meet high-performance needs.
Dynamic Host Configuration Protocol (DHCP) servers
provide the clients:
-A temp IP Address
- A default gateway
- Time server synchronization
Doesn’t provide - encryption protocols
Data in transit ( Secure)
TLS
DNSSEC
IPSec
- TLS
-DNSSEC:
Domain Name System Security Extensions (DNSSEC) protects data in transit by reducing the risk of DNS poisoning
-IPSEC - Transport Layer Security (TLS) and Internet Protocol Security (IPSec) reduce the risk of eavesdropping and interception of data.
OS Hardening
Remove default accounts
remove unnecessary services
Disallow local save of credentials
cloud storage cluster
A tightly coupled cloud storage cluster
SSD
Solid-state disks (SSDs) are used in cloud computing today because they operate at high speeds as compared to traditional spinning drives.
IETF
IANA
ISO/IEC
The IETF is an international organization of network designers and architects who work together in establishing standards and protocols for the Internet.
IANA oversees global IP address allocation among other Internet tasks.
the ISO/IEC develops, maintains and promotes standards in information technology and information communication technology.
ONF : An Organization Normative Framework (ONF)
ANF - application normative frameworks (ANFs)
An Organization Normative Framework (ONF) is a framework of so-called containers of application security best practices catalogued and leveraged by the organization and contains at least one or more subcomponents known as application normative frameworks (ANFs).
Brewer-Nash (Chinese Wall)
Brewer-Nash was specifically created for managed services arrangements, where an administrator for a given customer might also have access to a competitor’s data/environment; the model requires that administrators not be assigned to competing customers. In the modern cloud provider model, a cloud data center administrator will almost definitely have access to many customers from the same industry (i.e., competitors) but probably won’t even know it
Ports : DNS
DNS:53
google dns server 8.8.8.8.
DNSSEC : Adds digital signatures to DNS , Verify clients to check authenticity of DNS records
Network Ports
0 - 1023 - Wellknown ports
1024 - 49151 : registered ports
49152-65535 - dynamic ports
16bit binary numbers
2 power 16 values : 0 - 65,535
0 - 1023 - Wellknown ports
webservers - 80,
secure webserver - 443, mailservers
1024 - 49151 : registered ports
Microsoft reservers 1433 for sql server DB connection
Oracle server - 1521 for its own dbs
49152-65535 - dynamic ports
Administrative Services - Ports
21: FTP
22: SSH
3389 - RDP
137,138,139 - Windows -NetBIOS
53: DNS
Mail services:
25 : SMTP
110: POP (Post office protocol_
143 : IMAP
Webservices:
80: HTTP
443: HTTPS
ICMP - Internet Control Message Protocol
- PIng
-traceroute
eg: traceroute -I linkedin.com
PIng - identifies live system
-traceroute - identifies network path
ICANN
IP Addresses scarce
Private IP Address ranges
10.0.0.1 - 10.255.255.255
172.16.0.1 - 172.31.255.255
192.168.0.1-192.168.255.255