Cloud Security Architecture Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Architecture flashcards as text
Which type of cloud ACL evaluation logic uses Boolean combinations of attributes like department, clearance level, and resource sensitivity to make access decisions?
Answer: Attribute-Based Access Control (ABAC)
ABAC evaluates policies using attributes of the subject, resource, and environment to make fine-grained access control decisions.
A Kubernetes NetworkPolicy in a cloud-native deployment is most analogous to which traditional ACL concept?
Answer: Host-based firewall rules controlling pod-to-pod traffic
Kubernetes NetworkPolicies function like host-based firewall rules, controlling which pods can communicate with each other within the cluster.
When designing cloud ACLs for a PCI DSS-compliant environment, what is the minimum segmentation requirement for the cardholder data environment (CDE)?
Answer: Firewall ACLs must isolate the CDE from all other network zones
PCI DSS requires firewall-based network segmentation to isolate the CDE from untrusted networks and reduce the scope of compliance requirements.
In AWS, what is the effect of adding an explicit Deny in a Service Control Policy (SCP) on an AWS Organizations member account?
Answer: The deny applies even to the account's root user for the affected actions
SCPs restrict the actions available in member accounts including to the root user, though they do not affect the management account itself.
Which cloud security architecture pattern uses ACLs to enforce isolation between different customers sharing the same cloud infrastructure?
Answer: Multi-tenancy isolation via IAM and VPC segmentation
Cloud providers implement multi-tenancy isolation using IAM policies, VPC boundaries, and network ACLs to ensure one tenant cannot access another's resources.
What is a 'shadow ACL' risk in cloud security architecture?
Answer: Unintended permissions granted through inherited or wildcard ACL rules that bypass intended restrictions
Shadow ACLs occur when overly broad wildcard rules or inherited permissions grant unintended access that bypasses more specific restrictive rules.
In cloud ACL auditing, which approach is most effective for continuously detecting policy drift from a secure baseline?
Answer: Infrastructure-as-Code (IaC) policy scanning combined with runtime CSPM drift detection
Combining IaC scanning (preventive) with CSPM drift detection (detective) provides continuous coverage against policy changes that violate the security baseline.