Cloud Security Essentials
This test consists of questions related to Cloud computing technology, which are useful to computer science and gate aspirants.
Questions
Which of the following is termed as Detective controls in cloud security?
- These controls are used to upgrade the strength of the system by managing the vulnerabilities.
- This control will signal the preventative or corrective controls to address the issue in case of an attack.
- These controls reduce the effect of an attack.
- These controls are used to prevent any purposeful attack on a cloud system.
- These controls reduce the actual vulnerability of a system.
What is the difference between the corrective controls and the preventive controls in cloud security?
- Corrective controls use mechanisms to reduce the effect of an attack while preventive controls do not use any mechanism.
- Preventive controls do take the action when the attack occurs on the cloud system.
- Preventive controls signals the corrective controls about the attack on the cloud system.
- Preventive controls are used to upgrade the strength of the system while corrective are not.
- Both (1) and (3).
Which of the following is/are true about deterrent controls in cloud security?
- These controls prevent any attack in a cloud system by providing alerts to the system.
- These controls are used to upgrade the strength of the system by managing the vulnerabilities.
- These controls are used to recover the vulnerabilities of the system.
- These controls do not reduce the actual vulnerability of a system.
- Both (1) and (4).
Which of the following is known as 'scalability and performance' in cloud security architectural consideration?
- The cloud computing security implementation should support the large workloads and the underlying infrastructure.
- There should be a cloud security policy design that can be enforced consistently in both physical and virtual environments.
- The user credentials should be authenticated.
- The cloud security implementation should be automated.
- Both (1) and (4).
Which of the following is/are true about architectural consideration of cloud security?
- There should be a cloud security policy design for cloud security solution.
- The security controls need to be implemented to secure the logical entities.
- The cloud security needs to provisioned as a automated process.
- All of the above.
- Both (2) and (3).
Which of the following is/are cloud security solutions provides by Cisco?
- Secure cloud infrastructure
- Cloud security services
- Secure cloud access and communication solutions
- All of the above
- Both (2) and (3)
Which of the following is false about Cisco SecureX framework?
- It provides consistent security enforcement throughout the organization.
- It provides greater alignment of security policies with business needs.
- It provides Integrated global intelligence.
- It also provides Cisco Security Intelligence Operations (SIO) service.
- Both (3) and (4).
Which of the following compliances are included in the dimensions of cloud security?
- Logs and audit trails
- Data recovery and business continuity
- Additional security concerns around data jurisdiction
- All of the above
- Both (2) and (3)
Which of the following is not included in the ''security and privacy' dimension of cloud computing security?
- Identity management
- Availability
- Privacy
- Compliance
- Application security
What is/are the main security problem(s) that the customers face in cloud computing?
- The information among the customers is not isolated.
- The operations in the data center might cause data corruption and information leakage.
- The reliability problem in shared environment.
- Multiple cloud services at a time might cause authentication problems.
- All of the above.
Which of the following is not a compliance factor in cloud security?
- Reporting and auditing
- Platform integrity and security
- User privileges
- Data store compliance
- None of the above
What is data segregation in cloud computing security?
- Encryption problems can make data totally unusable.
- The sensitive data processed outside the enterprise might bring an inherent level of risk.
- Data segregation can cause policy related problems.
- The integrity of the data can be lost in Data segregation.
- Both (1) and (2).
Which of the following areas do the compliances and contracts cover in cloud security?
- Privacy
- Information Security Laws
- Auditing
- All of the above
- Both (2) and (3)
Which of the following is/are the security issues in the private clouds?
- The virtual machines belonging to different security zones, should not be hosted on the same virtual server.
- The host operating system must be free from malware.
- The host operating system should not have internet connectivity.
- There should be encryption and authentication mechanism at each network level.
- All of the above.
Which of the following phases are analysed in Microsoft Operations Framework for cloud security?
- Reduced IT service costs
- Improved business agility
- Deliver phase
- All of the above
- Both (1) and (2)