Cloud Security & Infrastructure Protection Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security & Infrastructure Protection flashcards as text
What is the recommended approach for managing privileged access in cloud environments?
Answer: Implementing just-in-time (JIT) access with least privilege principles
JIT access grants elevated permissions only when operationally required and for a limited duration, minimizing the attack surface while adhering to least privilege.
What security vulnerability is MOST associated with serverless (Function as a Service) architectures?
Answer: Event-data injection attacks via malicious data passed through function triggers
Serverless functions are triggered by events that can carry attacker-controlled data, making input validation against injection attacks a critical security concern.
Which control best addresses the risk of a cloud provider outage disrupting business operations?
Answer: Implementing multi-cloud or hybrid cloud redundancy strategies
Distributing workloads across multiple cloud providers or a hybrid environment eliminates single-provider dependency and improves resilience against outages.
What is Infrastructure as Code (IaC) security scanning?
Answer: Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment
IaC security scanning detects security misconfigurations in infrastructure templates before they are deployed, enabling shift-left security and preventing issues from reaching production.
Which encryption protocol version is considered best practice for protecting data in transit within cloud environments?
Answer: TLS 1.2 or higher for all cloud communications
TLS 1.2 and TLS 1.3 are the current industry standards for securing data in transit; earlier versions contain known vulnerabilities and should not be used.
What is a primary security advantage of immutable infrastructure in cloud environments?
Answer: It eliminates configuration drift and reduces the attack surface of long-running systems
Immutable infrastructure replaces instances rather than patching them, preventing configuration drift and ensuring every deployment starts from a known-good, consistent state.
What is the key security benefit of cloud-native security tools compared to third-party alternatives?
Answer: They offer deeper integration with provider APIs and native telemetry for broader visibility
Cloud-native security tools leverage deep API integration and platform telemetry that third-party tools cannot always access, enabling more comprehensive detection and automated response.