Cloud Security Architecture Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Architecture flashcards as text
In a multi-tenant cloud environment, which threat involves one tenant accessing another tenant's data or resources?
Answer: Tenant isolation breach
A tenant isolation breach occurs when logical or physical boundaries between tenants fail, allowing unauthorized cross-tenant data access.
Which NIST publication provides a cloud computing definition and identifies five essential characteristics of cloud computing?
Answer: NIST SP 800-145
NIST SP 800-145 defines cloud computing and its five essential characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.
What is 'data remanence' in the context of cloud decommissioning?
Answer: Residual data remaining on storage media after deletion
Data remanence refers to residual data that persists on storage media after deletion, posing a risk when cloud storage is reallocated to other tenants.
Which access control model is most suitable for enforcing attribute-based policies in cloud environments?
Answer: Attribute-Based Access Control (ABAC)
ABAC evaluates attributes of users, resources, and environment to make access decisions, making it highly flexible for dynamic cloud policies.
A company wants to ensure its SaaS vendor meets baseline security requirements. Which document formalizes these security expectations?
Answer: Security requirements annex or cloud security addendum
A security requirements annex or cloud security addendum formally documents and enforces the specific security controls expected from a SaaS vendor.
Which cloud security concept ensures that encryption keys are never exposed to the cloud provider in plaintext?
Answer: Bring Your Own Key (BYOK)
BYOK allows customers to generate and manage their own encryption keys, ensuring the cloud provider never has access to the plaintext key material.
In zero trust architecture applied to cloud environments, what principle replaces implicit network trust?
Answer: Continuous verification and least privilege access
Zero trust replaces implicit network trust with continuous verification of identity, device health, and least-privilege access regardless of network location.