Cloud Security Architecture Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Architecture flashcards as text
What is the primary risk of using a federated identity system to authenticate users to cloud services?
Answer: Compromise of the identity provider affects all federated services
If the identity provider (IdP) is compromised, attackers can gain access to all services that trust it, making the IdP a critical single point of failure.
Which network segmentation technique is commonly used in cloud environments to isolate workloads at layer 3?
Answer: Subnet-level security groups and NACLs
Cloud subnets with security groups and Network Access Control Lists (NACLs) provide layer 3/4 isolation between workloads within a VPC.
When migrating sensitive workloads to the cloud, what is the recommended approach for assessing residual risk?
Answer: Identify, evaluate, and apply controls to reduce risk to an acceptable level
Risk management requires identifying threats, evaluating their impact and likelihood, and applying controls to bring residual risk within the organization's risk appetite.
Which cloud logging service would an auditor primarily examine to verify API call history in AWS?
Answer: AWS CloudTrail
AWS CloudTrail records all API calls and management events, providing the audit trail needed to verify who did what and when in an AWS environment.
What is a 'security group' in most cloud provider implementations?
Answer: A stateful virtual firewall controlling inbound and outbound traffic to resources
A security group is a stateful virtual firewall that controls traffic to and from cloud resources based on protocol, port, and source/destination rules.
Which type of cloud storage is most vulnerable to data leakage due to misconfigured access permissions?
Answer: Object storage buckets
Object storage buckets (e.g., S3) are frequently misconfigured with public access, making them a leading cause of cloud data breaches.
In the context of cloud security, what does 'infrastructure as code' (IaC) scanning address?
Answer: Identifying security misconfigurations in cloud resource templates before deployment
IaC scanning analyzes templates (e.g., Terraform, CloudFormation) for security misconfigurations before they are deployed to production.