โ† All CAP Flashcard Decks

Cloud Security Architecture Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Security Architecture flashcards as text
  1. What is the main security advantage of using immutable infrastructure in cloud deployments?

    Answer: It prevents any configuration changes at runtime, reducing drift and attack surface

    Immutable infrastructure replaces rather than modifies running instances, eliminating configuration drift and reducing the window for persistent attacker footholds.

  2. Which cloud security architecture pattern places a security inspection layer between internet traffic and cloud-hosted applications?

    Answer: Cloud-native WAF and reverse proxy

    A cloud-native WAF (Web Application Firewall) and reverse proxy inspect and filter inbound HTTP/S traffic before it reaches the application tier.

  3. A CAP practitioner is reviewing a cloud system's ATO package. Which document describes how security controls are implemented in the cloud environment?

    Answer: System Security Plan (SSP)

    The System Security Plan (SSP) documents how each security control is implemented, including those specific to the cloud architecture.

  4. What risk does 'vendor lock-in' present from a cloud security architecture perspective?

    Answer: Reduced portability and limited ability to migrate if the provider suffers a breach or outage

    Vendor lock-in reduces an organization's ability to migrate workloads if security, compliance, or availability issues arise with the cloud provider.

  5. Which security control helps detect anomalous cloud API calls that may indicate compromised credentials?

    Answer: User and Entity Behavior Analytics (UEBA)

    UEBA establishes behavioral baselines and alerts on deviations, making it effective at detecting compromised credential misuse in cloud API activity.

  6. In a containerized cloud environment, which security practice limits the blast radius of a compromised container?

    Answer: Applying least-privilege Linux capabilities and read-only file systems

    Dropping unnecessary Linux capabilities and mounting file systems read-only limits what an attacker can do if a container is compromised.

  7. What is the role of a Hardware Security Module (HSM) in cloud key management?

    Answer: It provides tamper-resistant hardware for generating and protecting cryptographic keys

    An HSM is a dedicated hardware device that generates, stores, and protects cryptographic keys in a tamper-evident and tamper-resistant environment.