Cloud Security & Infrastructure Protection Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security & Infrastructure Protection flashcards as text
Which framework was specifically designed to address cloud computing security controls?
Answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix is a cybersecurity control framework developed by the Cloud Security Alliance specifically for cloud computing environments.
What does FedRAMP primarily govern?
Answer: Security requirements for cloud services used by U.S. federal government agencies
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services procured by U.S. federal agencies.
Which principle best describes 'zero trust' architecture as applied to cloud environments?
Answer: Never implicitly trusting any user, device, or network segment regardless of location
Zero trust assumes no entity is inherently trustworthy and requires continuous verification of identity, device health, and authorization for every access request.
What is a key security consideration when cloud services process data belonging to EU citizens?
Answer: GDPR compliance requirements including data subject rights and cross-border transfer restrictions
GDPR imposes obligations on any organization handling EU citizen data, including honoring data subject rights and restricting transfers of that data outside the European Economic Area.
From a security perspective, what does a Service Level Agreement (SLA) with a cloud provider typically address?
Answer: Guaranteed uptime commitments, incident response timelines, and division of security responsibilities
SLAs establish measurable commitments for availability, incident notification windows, and clarify the boundary of security responsibilities between provider and customer.
What is the significance of a 'right to audit' clause in a cloud service contract?
Answer: It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture
A right-to-audit clause allows the customer to independently verify that the cloud provider's security controls and compliance posture meet contractual and regulatory obligations.
Which security control is MOST effective at preventing unauthorized data exfiltration from a cloud storage service?
Answer: Implementing data loss prevention (DLP) policies with egress monitoring and blocking
DLP policies inspect outbound data flows and can block or alert on unauthorized transfers of sensitive information, directly addressing exfiltration risk.