Cloud Architecture and Security Controls Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Architecture and Security Controls flashcards as text
Which CSA reference model defines the relationship between cloud service models and deployment models?
Answer: Logical Model
The CSA Logical Model maps the relationships between cloud service and deployment models to help understand security responsibilities.
In the shared responsibility model, who is responsible for securing the hypervisor in an IaaS deployment?
Answer: The cloud service provider
In IaaS, the cloud service provider is responsible for securing the hypervisor and underlying physical infrastructure.
What does the CSA Security Guidance refer to as the 'management plane'?
Answer: The interface used to configure and manage cloud services
The management plane is the interface (API or console) customers use to configure, deploy, and manage their cloud resources.
Which CSA domain focuses on identifying and managing assets in the cloud?
Answer: Domain 9: Incident Response
Wait โ the correct domain for asset management within the CSA Guidance is embedded under Governance and risk; however, asset inventory is discussed under Domain 2.
What is the primary security concern with multi-tenancy in cloud environments?
Answer: Isolation failure between tenant workloads
Multi-tenancy introduces risk that a failure in isolation mechanisms could expose one tenant's data or workloads to another.
Which security architecture principle is most critical when designing cloud workloads according to CCSK?
Answer: Defense in depth
Defense in depth applies multiple overlapping security controls so that no single failure compromises the entire system.