Sec + 3 Flashcards

(32 cards)

1
Q

What is vm sprawl? How to prevent?

A

Vm getting too big to protect.
Access control, segmentation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a cloud access security broker?

A

Fosters relationship between business and the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Supply chain problems

A

Bad provider
Bad hardware
Bad software
Weak configs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is session replay? And how to prevent?

A

Stealing tokens, like cookies, to use later. Kerberos prevents it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a collision attack?

A

2 docs with same hash. 1 malicious, 1 benign and signing the benign one and switching it with the malicious one.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Ways to segment systems

A
  1. Physical
  2. Vlan
  3. Subnetting
  4. Micro-segmentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Hardening techniques in general

A

Encryption
Continuous monitoring
Threat detection
Alert generation
Response and remediation
Real time threat mitigation
Endpoints visibility
Firewall
Ips, ids
Diable unused ports
Removal of unnecessary software and hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How to secure a network?

A

Firewalls
ACL’s
Ids, ips
Siem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How to secure endpoints

A
  1. Anti-virus
  2. Edr
  3. mobile device management mdm
  4. multi factor I’d, mfa
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a community cloud?

A

Multiple companies share a cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 5 cloud services?

A
  1. IaaS, infrastructure. Gives most control
  2. SaaS, software as a service hosts an app like Salesforce
  3. PaaS, platform, tools to build apps
  4. SaaS, security
  5. XaaS, anything.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Vendor security issues

A

Company vulnerabilities
Software vulnerabilities
Compliance challenges
Vendor downtime or problems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is IaC?

A

Infrastructure as code. Resources are managed and provisioned with code. This allows automation to eliminate manual necessity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

IoT problems?

A

No standardization
Data privacy concerns
Unsecured communication
Lifecycle management
Physical attacks
Supply chain risks
User awareness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a software defined wide area network?

A

Encrypting data across the wan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

2 Load balancer states

A
  1. Active/active. Many working together. If 1 fails the others take over.
  2. Active/passive. Passive takes over when Active fails
17
Q

What is clustering?

A

Grouping multiple servers or nodes together to operate as a single system.

18
Q

How does clustering work?

A

Has an active node and a passive node that share a disc, called a quorum. Watched by a witness server to see if the active node goes down with a heartbeat communicator and a virtual ip.

19
Q

What is local redundant storage?

A

3 copies in single zone.

20
Q

What is zone redundant storage?

A

3 copies in 3 zones in same region

21
Q

What is georedundant storage?

A

Storing in three separate regions

22
Q

What are the benefits of platform diversity?

A

Redundancy
Adaptability
Threat resilience
Enhanced recovery
Compliance

23
Q

Benefits of multi cloud systems?

A

Less downtime
Flexibility and choice
Cost optimization
Avoid Vendor lock in

24
Q

Downside of multi cloud systems?

A

Complexity
Security and compliance
Cost
Integration

25
What is continuity of operation (coop)
Plans to keep a company running in a disaster
26
Benefits of coop?
Continuity of operations Builds resilience and redundancy Need communication plans Personal preparedness Revise and update
27
People capacity planning considerations
1. Skill assessments 2. Workload 3. Talent acquisition 4. Succession planning
28
Tech capacity planning requirements.
Scalability Upgrades Security and compliance Innovation and emerging tech
29
Infrastructure capacity planning consideration
Expandsion and optimization Energy efficiency Disaster recovery
30
What is differential backups?
More than incremental but less than full
31
Back up considerations
1. On/offsite 2. Frequency 3. Encryption 4. Snapshots 5. Recovery 6. Replication 7. Journaling- change journal
32
Power considerations
1. Generators 2. Uninterrupted power supply (UPS) 3. Power distribution units (PDU) MITIGATES SPIKES, blackouts. Balanced power