โ† All CSS Flashcard Decks

Cloud Security & Infrastructure Protection Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Security & Infrastructure Protection flashcards as text
  1. What is the recommended approach for managing privileged access in cloud environments?

    Answer: Implementing just-in-time (JIT) access with least privilege principles

    JIT access grants elevated permissions only when operationally required and for a limited duration, minimizing the attack surface while adhering to least privilege.

  2. What security vulnerability is MOST associated with serverless (Function as a Service) architectures?

    Answer: Event-data injection attacks via malicious data passed through function triggers

    Serverless functions are triggered by events that can carry attacker-controlled data, making input validation against injection attacks a critical security concern.

  3. Which control best addresses the risk of a cloud provider outage disrupting business operations?

    Answer: Implementing multi-cloud or hybrid cloud redundancy strategies

    Distributing workloads across multiple cloud providers or a hybrid environment eliminates single-provider dependency and improves resilience against outages.

  4. What is Infrastructure as Code (IaC) security scanning?

    Answer: Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment

    IaC security scanning detects security misconfigurations in infrastructure templates before they are deployed, enabling shift-left security and preventing issues from reaching production.

  5. Which encryption protocol version is considered best practice for protecting data in transit within cloud environments?

    Answer: TLS 1.2 or higher for all cloud communications

    TLS 1.2 and TLS 1.3 are the current industry standards for securing data in transit; earlier versions contain known vulnerabilities and should not be used.

  6. What is a primary security advantage of immutable infrastructure in cloud environments?

    Answer: It eliminates configuration drift and reduces the attack surface of long-running systems

    Immutable infrastructure replaces instances rather than patching them, preventing configuration drift and ensuring every deployment starts from a known-good, consistent state.

  7. What is the key security benefit of cloud-native security tools compared to third-party alternatives?

    Answer: They offer deeper integration with provider APIs and native telemetry for broader visibility

    Cloud-native security tools leverage deep API integration and platform telemetry that third-party tools cannot always access, enabling more comprehensive detection and automated response.