← All CAP Flashcard Decks

Cloud Security Architecture Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cloud Security Architecture flashcards as text
  1. Which cloud deployment model places infrastructure on-premises but uses cloud management tools and APIs?

    Answer: Private cloud

    Private cloud hosts infrastructure on-premises (or dedicated facilities) while leveraging cloud-like management tools and APIs.

  2. In a shared responsibility model, who is responsible for patching the hypervisor in an IaaS environment?

    Answer: The cloud service provider

    In IaaS, the cloud service provider owns and patches the hypervisor layer; the customer manages OS and above.

  3. What is the primary purpose of a Cloud Access Security Broker (CASB)?

    Answer: Enforce security policies between users and cloud services

    A CASB acts as an intermediary to enforce security policies, visibility, and compliance between enterprise users and cloud services.

  4. Which encryption key management approach gives an organization the most control over its keys in a cloud environment?

    Answer: Customer-managed keys (CMK)

    Customer-managed keys (CMK) allow the organization to generate, store, rotate, and revoke keys independently of the cloud provider.

  5. A virtual private cloud (VPC) peering connection allows two VPCs to communicate — what is a key security consideration?

    Answer: Overly permissive security groups can expose resources across both VPCs

    VPC peering routes traffic privately, but misconfigured security groups or NACLs can unintentionally expose resources in both VPCs.

  6. Which framework specifically addresses cloud security controls and is published by the Cloud Security Alliance?

    Answer: Cloud Controls Matrix (CCM)

    The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) is a cybersecurity control framework specifically designed for cloud environments.

  7. What does the concept of 'elasticity' in cloud computing introduce as a security concern?

    Answer: Attack surface expansion during auto-scaling events

    Auto-scaling can rapidly expand the attack surface by spinning up new instances that may not have the latest security patches or configurations applied.