




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
第三章練習(xí)題1.Youareinchargeofcreatingthebusinesscontinuityanddisasterrecovery(BC/DR)planandproceduresforyourorganization.Yourorganizationhasitsproductionenvironmenthostedinacloudenvironment.YouareconsideringusingcloudbackupservicesforyourBC/DRpurposesaswell.Whatwouldprobablybethebeststrategyforthisapproach,intermsofredundancyandresiliency?[單選題]A.HaveyourcloudprovideralsoprovideBC/DRbackup.B.KeepaBC/DRbackuponthepremisesofyourcorporateheadquarters.C.UseanothercloudproviderfortheBC/DRbackup.(正確答案)D.Moveyourproductionenvironmentbackintoyourcorporatepremises,anduseyourcloudprovidertohostyourBC/DRbackup.答案解析:C.It’sbesttohaveyourbackupatanothercloudproviderincasewhatevercausesaninterruptioninserviceoccursthroughoutyourprimaryprovider’senvironment;thiswillbemorecomplicatedandexpensive,butitprovidesthebestredundancyandresiliency.Usingthesameproviderforproductionandbackupisnotabadoption,butitentailstheriskofthesamecontingencyaffectingbothcopiesofyourdata.Havingeitherthebackuportheproductionenvironmentlocalizeddoesnotprovidethebestprotection,soneitheroptionBnoroptionDisdesirable.2.Youareinchargeofcreatingthebusinesscontinuityanddisasterrecovery(BC/DR)planandproceduresforyourorganization.YoudecidetohaveatabletoptestoftheBC/DRactivity.Whichofthefollowingwillofferthebestvalueduringthetest?[單選題]A.Haveallparticipantsconducttheirindividualactivitiesviaremotemeetingtechnology.B.TaskamoderatorwellversedinBC/DRactionstosuperviseandpresentscenariostotheparticipants,includingrandomizedspecialevents.(正確答案)C.ProvidecopiesoftheBC/DRpolicytoallparticipants.D.Allowallusersinyourorganizationtoparticipate.答案解析:B.Atrainedandexperiencedmoderatorcanguidetheparticipantsthroughtheactivity,enhancingtheirtrainingandnotingpitfallsandareasforimprovement.OptionAisnotpreferablebecausehavingtheparticipantsgatheredtogetherensurestheirfullattentionandprovidesinteractionthatremoteparticipationmightnotyield.OptionCisabaseline;allparticipantsshouldhavecopiesofthepolicyasamatterofcourse.OptionDisnotusefulinatabletopexercise;onlycriticalparticipantsintheorganizationshouldtakepartinthetabletop.3.Youareinchargeofcreatingthebusinesscontinuityanddisasterrecovery(BC/DR)planandproceduresforyourorganization.Yourorganizationhasitsproductionenvironmenthostedbyacloudprovider,andyouhaveappropriateprotectionsinplace.WhichofthefollowingisasignificantconsiderationforyourBC/DRbackup?[單選題]A.EnoughpersonnelattheBC/DRrecoverysitetoensureproperoperationsB.Goodcryptographickeymanagement(正確答案)C.AccesstotheserverswheretheBC/DRbackupisstoredD.Forensicanalysiscapabilities答案解析:B.Thisisadifficultquestionthatrequiresagreatdealofthought.OptionBiscorrectbecauseappropriateclouddatasecuritypracticeswillrequireencryptingagreatdealofthedata,andhavingthekeyswillbenecessaryduringcontingencyoperationsinorderto
accessthebackup;withoutthekeys,youwon’tbeabletoaccessyourdata.OptionAisnotcorrectbecauseusingthecloudforBC/DRwillallowpersonneltoaccessthebackupfromanywheretheycangetbroadbandconnectivity,notspecificallyarecoverysite.Option
Cisnotcorrectbecausethecustomerwillrarelyhavephysicalaccesstoserversinthecloudenvironment.OptionDisnotcorrectbecauseforensicanalysisisnotasignificantconsiderationinBC/DR;itismuchmoreimportantforincidentresponse.4.Youareinchargeofcreatingthebusinesscontinuityanddisasterrecovery(BC/DR)planandproceduresforyourorganization.YouaregoingtoconductafulltestoftheBC/DRplan.Whichofthefollowingstrategiesisanoptimumtechniquetoavoidmajorissues?[單選題]A.Haveanotherfullbackupoftheproductionenvironmentstoredpriortothetest.(正確答案)B.Assignallpersonneltaskstoperformduringthetest.C.Havethecloudproviderimplementasimulateddisasteratarandommomentinordertomaximizerealistictesting.D.Haveyourregulatorspresentatthetestsotheycanmonitorperformance.答案解析:A.Afulltestwillinvolveboththeproductionenvironmentandthebackupdata;itispossibletocreateanactualdisasterduringafulltestbyruiningtheavailabilityofboth.Therefore,itiscrucialtohaveafullbackup,distinctfromtheBC/DRbackup,inordertorollbackfromthetestincasesomethinggoeshorriblywrong.OptionBisincorrect
becausenotallpersonnelwillhavetaskstoperform;mostpersonnelwillhavetoevacuatefromthefacilityonlyduringafulltest.OptionCisincorrectbecausethecloudprovidershouldnotinitiatethetest,andthetestshouldnottakeplaceatarandommoment.OptionDisnotcorrectbecausetheregulators’presencewillnotaddanyvaluetothetest.5.ASecurityAssertionMarkupLanguage(SAML)identityassertiontokenusestheprotocol.[單選題]A.ExtensibleMarkupLanguage(XML)(正確答案)B.HypertextTransferProtocol(HTTP)C.HypertextMarkupLanguage(HTML)D.AmericanStandardCodeforInformationInterchange(ASCII)答案解析:A.SecurityAssertionMarkupLanguage(SAML)isbasedonXML.HTTPisusedforport80webtraffic;HTMLisusedtopresentwebpages.ASCIIistheuniversalalphanumericcharacterset.6.Theminimumessentialcharacteristicsofaclouddatacenterareoftenreferredtoas“ping,power,pipe.”Whatdoesthistermmean?[單選題]A.Remoteaccessforcustomertorackeddevicesinthedatacenter;electricalutilities;connectivitytoanInternetserviceprovider(ISP)/theInternet(正確答案)B.Applicationsuitability;availability;connectivityC.Infrastructureasaservice(IaaS);softwareasaservice(SaaS);platformasaservice(PaaS)D.Anti-malwaretools;controlsagainstdistributeddenialofservice(DDoS)attacks;physical/environmentalsecuritycontrols,includingfiresuppression答案解析:A.OptionAisthedefinitionoftheterm;theotheranswersarenot.7.TosupportallaspectsoftheCIAtriad(confidentiality,integrity,availability),allofthefollowingaspectsofaclouddatacenterneedtobeengineeredwithredundanciesexcept[單選題]A.PowersupplyB.HVACC.Administrativeoffices(正確答案)D.Internetserviceprovider(ISP)/connectivitylines答案解析:C.Theadministrativeofficesofaclouddatacenterrarelyarepartofthecriticalfunctionsoftheoperation;adatacentercouldlikelyendurethelossoftheadministrativeofficesfor
aconsiderablelengthoftime,soredundancyhereisprobablynotcosteffective.Alltheotheritemspartofthecriticalpathandneedredundancies.8.Whoisthecloudcarrier?[單選題]A.ThecloudcustomerB.ThecloudproviderC.Theregulatoroverseeingthecloudcustomer’sindustryD.TheISPbetweenthecloudcustomerandprovider(正確答案)答案解析:C.Theadministrativeofficesofaclouddatacenterrarelyarepartofthecriticalfunctionsoftheoperation;adatacentercouldlikelyendurethelossoftheadministrativeofficesfor
aconsiderablelengthoftime,soredundancyhereisprobablynotcosteffective.Alltheotheritemspartofthecriticalpathandneedredundancies.9.Whichofthefollowingtermsdescribesameanstocentralizelogicalcontrolofallnet-workednodesintheenvironment,abstractedfromthephysicalconnectionstoeach?[單選題]A.Virtualprivatenetwork(VPN)B.Software-definednetwork(SDN)(正確答案)C.Accesscontrollists(ACLs)D.Role-basedaccesscontrol(RBAC)答案解析:B.Thequestiondescribesasoftware-definednetwork(SDN).
AVPNisusedforcreatinganencryptedcommunicationstunneloveranuntrustedmedium,sooptionAisincorrect.
ACLsareusedascentralizedrepositoriesforidentification,authentication,andauthoriza-tionpurposes,sooptionCisincorrect.
RBACisanaccesscontrolmodelusedtoassignpermissionsbasedonjobfunctionswithinanorganization,sooptionDisincorrect.10.Insoftware-definednetworking(SDN),thenorthboundinterface(NBI)usuallyhandlestrafficbetweentheandthe[單選題]A.Cloudcustomer;ISPB.SDNcontrollers;SDNapplications(正確答案)C.Cloudprovider;ISPD.Router;host答案解析:B.TheNBIusuallyhandlestrafficbetweentheSDNcontrollersandSDNapplications.
OptionsAandCareincorrectbecauseneitherofthoseoptionslistsanyoftheSDNinfra-structure,bethatthecontrollersortheapplications.OptionDmaybearguablycorrect,
astheremightbeanNBIhandlingthattrafficbetweenthosenodes,butoptionBismorespecificandalwaystrueforthisdefinition,soitisthebetterchoice.11.Software-definednetworking(SDN)allowsnetworkadministratorsandarchitectstoper-formallthefollowingfunctionsexcept[單選題]A.ReroutetrafficbasedoncurrentcustomerdemandB.CreatelogicalsubnetswithouthavingtochangeanyactualphysicalconnectionsC.FilteraccesstoresourcesbasedonspecificrulesorsettingsD.Deliverstreamingmediacontentinanefficientmannerbyplacingitclosertotheenduser(正確答案)答案解析:D.OptionDisreallyadefinitionofaCDN(contentdeliverynetwork).
AlltheotheroptionsareaspectsofSDNs.12.Whichofthefollowingisadevicespeciallypurposedtohandletheissuance,distribution,andstorageofcryptographickeys?[單選題]A.Keymanagementbox(KMB)B.Hardwaresecuritymodule(HSM)(正確答案)C.Ticket-grantingticket(TGT)D.Trustedcomputingbase(TCB)答案解析:B.ThequestiondescribesanHSM.
KMBisanonsensetermusedasadistractor,soitisincorrect.
TGTisatermassociatedwithKerberossinglesign-onsystemsandisincorrect.
TheTCBincludestheelementsofhardwareandsoftware(usuallyintheoperatingsystem)thatensurethatasystemcanonlybecontrolledbythosewiththeproperpermissions(i.e.,adminswithrootcontrol),soitisalsoincorrect.13.Whendiscussingthecloud,weoftensegregatethedatacenterintothetermscomputestorage,andnetworking.Computeismadeupofand[單選題]A.Routers;hostsB.Applicationprogramminginterface(APIs);northboundinterface(NBIs)C.Centralprocessingunit(CPU);random-accessmemory(RAM)(正確答案)D.Virtualized;actualhardwaredevices答案解析:C.Thecomputenodesofaclouddatacentercanbemeasuredintermsofhowmanycentralprocessingunits(CPUs)andhowmuchrandomaccessmemory(RAM)isavailablewithinthecenter.
OptionAisincorrectbecauserouterswouldbeconsideredapartofthenetworkingofadatacenter(andbecauseoptionCisabetteranswer).
OptionBinvolvesapplicationsandhowtrafficflowsbetweenthemandstoragecontrol-lers;ithasnothingtodowiththecomputenodesandisthereforewrong.
OptionDmightobliquelybeconsideredcorrectbecauseit’stechnicallytrue(computenodeswillincludebothvirtualandhardwaremachines),butoptionCisamuchbetterandmoreaccuratechoice.14.Allofthefollowingcanbeusedtoproperlyapportioncloudresourcesexcept[單選題]A.ReservationsB.SharesC.Cancellations(正確答案)D.Limits答案解析:C.Cancellationsisnotatermusedtodescribearesourceallotmentmethodology.Alloftheotheroptionsaresuchterms.15.Whichofthefollowingisamethodforapportioningresourcesthatinvolvessettingguar-anteedminimumsforalltenants/customerswithintheenvironment?[單選題]A.Reservations(正確答案)B.SharesC.CancellationsD.Limits答案解析:A.Thequestionisthedefinitionofreservations.
OptionsBandDarealsoresourceapportioningmethods,buttheydonotfallunderthedefinitiondescribedinthequestion.16.Whichofthefollowingisamethodforapportioningresourcesthatinvolvessettingmaxi-mumusageamountsforalltenants/customerswithintheenvironment?[單選題]A.ReservationsB.SharesC.CancellationsD.Limits(正確答案)答案解析:D.Thequestiondescribeslimits.
OptionsAandBarealsoresourceapportioningmethods,buttheydonotfallunderthedefinitiondescribedinthequestion.
OptionCisbecauseithasnomeaninginthiscontext.17.Whichofthefollowingisamethodforapportioningresourcesthatinvolvesprioritizingresourcerequeststoresolvecontentionsituations?[單選題]A.ReservationsB.Shares(正確答案)C.CancellationsD.Limits答案解析:D.Thequestiondescribeslimits.
OptionsAandBarealsoresourceapportioningmethods,buttheydonotfallunderthedefinitiondescribedinthequestion.
OptionCisbecauseithasnomeaninginthiscontext.18.Abare-metalhypervisorisType[單選題]A.1(正確答案)B.2C.3D.4答案解析:A.Abare-metalhypervisorisaType1hypervisor.
OptionBdescribesanothertypeofhypervisor;theotheroptionsareincorrectbecausethereisnosuchthingasaType3orType4hypervisor.19.Ahypervisorthatrunsinsideanotheroperatingsystem(OS)isaTypehypervisor.[單選題]A.1B.2(正確答案)C.3D.4答案解析:B.ThequestiondescribesaType2hypervisor.
OptionAdescribesanothertypeofhypervisor;theotheroptionsareincorrectbecausethereisnosuchthingasaType3orType4hypervisor.20.ATypehypervisorisprobablymoredifficulttodefendthanotherhypervisors.[單選題]A.1B.2(正確答案)C.3D.4答案解析:B.AType2hypervisorreliesontheunderlyingoperatingsystem(OS)tooperateproperly;
theunderlyingOSoffersalargeattacksurfaceforaggressors.
AType1hypervisorbootsdirectlyfromthehardware;it’smucheasiertosecureamachine’sBasicInput/OutputSystem(BIOS)thananentireOS,sooptionBisbetterthanoptionA.
OptionsCandDareincorrectbecausethereisnosuchthingasaType3orType4hypervisor.21.Oneofthesecuritychallengesofoperatinginthecloudisthatadditionalcontrolsmustbeplacedonfilestoragesystemsbecause[單選題]A.FilestoresarealwayskeptinplaintextinthecloudB.ThereisnowaytosanitizefilestoragespaceinthecloudC.Virtualizationnecessarilypreventstheuseofapplication-basedsecuritycontrolsD.Virtualmachinesarestoredassnapshottedfileswhennotinuse(正確答案)答案解析:D.VMsaresnapshottedandsimplystoredasfileswhentheyarenotbeingused;anattackerwhogainsaccesstothosefilestorescouldostensiblystealentiremachinesinhighlyportable,easilycopiedformats.Therefore,thesecloudstoragespacesmustincludeasignificantamountofcontrols.
OptionsAandCaresimplyuntrue.
OptionBisuntruewhencrypto-shreddingisutilized.22.Whatisthemainreasonvirtualizationisusedinthecloud?[單選題]A.Virtualmachines(VMs)areeasiertoadminister.B.IfaVMisinfectedwithmalware,itcanbeeasilyreplaced.C.WithVMs,thecloudproviderdoesnothavetodeployanentirehardwaredeviceforeverynewuser.(正確答案)D.VMsareeasiertooperatethanactualdevices.答案解析:C.WhileoptionsAandBarebothalsotrue,CisthemostsignificantreasonclouddatacentersuseVMs.Ifthecloudproviderhadtopurchaseanewboxforeveryuser,thecostofcloudserviceswouldbeasmuchasrunningatraditionalenvironment(orlikelycostevenmore),andtherewouldbenoreasonforanyorganizationtomigratetothecloud,especiallyconsideringtherisksassociatedwithdisclosingdatatoathirdparty.
OptionDissimplyuntrue.VMsarenoteasiertooperatethanactualdevices.23.Orchestratingresourcecallsisthejobofthe[單選題]A.AdministratorB.RouterC.VMD.Hypervisor(正確答案)答案解析:D.Thequestiondescribeswhatthehypervisordoes.(Notethattheanswer“operatingsystem”wouldalsoworkherebutwasnotoneoftheoptions.)
OptionAisincorrect;theallocationofresourcesisnotperformedmanually.
Therouterdirectstrafficbetweennetworks;itdoesnotapportionresources.Therefore,optionBisincorrect.
AVMmakesresourcecalls;optionCisincorrect.24.Whichofthefollowingtermsdescribesacloudstorageareathatusesafilesystem/hierarchy?[單選題]A.VolumestorageB.Objectstorage(正確答案)C.Logicalunitnumber(LUN)D.Blockstorage答案解析:B.Objectstorageis,literally,ameansofstoringobjectsinahierarchysuchasafiletree.
Alltheotheroptionsaretermsusedtodescribecloudstorageareaswithoutfilestructures.25.Typically,whichformofcloudstorageisusedintheneartermforsnapshottedvirtualmachine(VM)images?[單選題]A.VolumestorageB.Objectstorage(正確答案)C.Logicalunitnumber(LUN)D.Blockstorage答案解析:B.SnapshottedVMimagesareusuallykeptinobjectstorage,asfiles.
AlltheotheroptionsareincorrectandoptionCisnotatypeofstorage.26.Whooperatesthemanagementplane?[單選題]A.RegulatorsB.EndconsumersC.Privilegedusers(正確答案)D.Privacydatasubjects答案解析:C.Onlythemosttrustedadministratorsandmanagerswillhaveaccesstotheclouddatacenter’smanagementplane.Thesewillusuallybecloudprovideremployees,butsomecloudcustomerpersonnelmaybegrantedlimitedaccesstoarrangetheirorganization’scloudresources.
Regulatorsdonotoperateacustomer’smanagementplane,sooptionAisincorrect.OptionBisambiguous.However,aconsumerofdataisunlikelytohavebeengiventhe
elevatedprivilegesnecessaryofoperatethemanagementplaneinacloudenvironment.
OptionBisincorrect.
OptionDisalsoanambiguousanswer.Onlythemosttrustedadministratorsandmanagershaveaccesstotheclouddatacenter’smanagementplane.Aprivacydatasubjectisneitheramosttrustedadministratornoratrustedmanager.Therefore,optionDisincorrect.27.Whatisprobablytheoptimumwaytoavoidvendorlock-in?[單選題]A.Usenonproprietarydataformats.B.Useindustry-standardmedia.C.Usestrongcryptography.D.Usefavorablecontractlanguage.(正確答案)答案解析:D.Thecontractisprobablythecloudcustomer’sbesttoolforavoidingvendorlock-in;contracttermswillestablishhoweasyitistomigrateyourorganization’sdatatoanotherproviderinatimely,cost-effectivemanner.
OptionsAandBarealsoimportantwaystoavoidvendorlock-in,butDisthebestwer.
OptionCisincorrectandwillnotaidinavoidingvendorlock-in.28.Whowilldeterminewhetheryourorganization’scloudmigrationissatisfactoryfromacomplianceperspective?[單選題]A.ThecloudproviderB.ThecloudcustomerC.Theregulator(s)(正確答案)D.TheInternetserviceprovider(ISP)答案解析:C.Theregulator(s)overseeingyourindustry/organizationwillmakethefinaldeterminationastowhetheryourcloudconfigurationissuitabletomeettheirrequirements.Itisbesttocoordinatewithyourregulator(s)whenfirstconsideringcloudmigration.
Cloudproviders,cloudcustomers,andISPsarenotparticularlyconcernedaboutwhetheranorganization’smigrationissatisfactoryfromacomplianceperspective.Thewords,“complianceperspective”shouldautomaticallybringtomindregulator(s).OptionsA,B,andDarethereforeincorrectanswers.29.Whatisprobablythebestwaytoavoidproblemsassociatedwithvendorlock-out?[單選題]A.Usestrongcontractlanguage.B.Usenonproprietarydataandmediaformats.C.Usestrongcryptography.D.Useanotherproviderforbackuppurposes.(正確答案)答案解析:D.Vendorlock-outoccurswhentheprovidersuddenlyleavesthemarket,asduringabankruptcyoracquisition.Therisksassociatedwithlock-outincludedenialofservice,becauseoftotalunavailabilityofyourdata.Thebestwaytohandletheserisksistohaveanother,fullbackupofyourdatawithanothervendorandtheabilitytoreconstitute
youroperatingenvironmentinatimeframethatdoesn’texceedyourrecoverytimeobjective(RTO).
Theotheroptionsdonotaidinaddressingvendorlock-out.30.Inapubliccloudservicesarrangement,whocreatesgovernancethatwilldeterminewhichcontrolsareselectedforthedatacenterandhowtheyaredeployed?[單選題]A.Thecloudprovider(正確答案)B.ThecloudcustomerC.Theregulator(s)D.Theenduser答案解析:A.Becausethecloudproviderownsandoperatestheclouddatacenter,theproviderwillcraftandpromulgatethegovernancethatdeterminesthecontrolselectionandusage.Thisisanotherriskthecloudcustomermustconsiderwhenmigratingintothecloud;thecustomer’sgovernancewillnolongerhavedirectprecedenceovertheenvironmentwherethecustomer’sdataislocated.
Boththecloudcustomerandtheregulator(s)mayhavespecificcontrolmandatesthatmightrequirethecustomertodeployadditionalsecuritycontrols(atthecustomerside,withinthedata,asagentsontheuserdevices,orontheprovidersideorinapplicationprogramminginterfaces[APIs]asallowedbytheservicemodelorcontract),sooptionsBandCarealsopartiallytrue,butAisabetteranswerasitismoregeneral.
OptionDuntruebecausetheenduserdoesnotdeterminewhichcontrolsareselectedfortheclouddatacenterandhowtheyaredeployed.Thatistheresponsibilityofthecloudprovider.31.Whatisthetermthatdescribesthesituationwhenamalicioususerorattackercanexittherestrictionsofavirtualmachine(VM)andaccessanotherVMresidingonthesamehost?[單選題]A.HostescapeB.Guestescape(正確答案)C.ProviderexitD.Escalationofprivileges答案解析:B.Thequestiondescribesaguestescape.
OptionsAandCareotherrisksofoperatinginthecloud.OptionDcanleadtoAorB,butBdescribesthemorespecificsituationandthereforethecorrectanswer.32.Whatisthetermthatdescribesthesituationwhenamalicioususerorattackercanexittherestrictionsofasinglehostandaccessothernodesonthenetwork?[單選題]A.Hostescape(正確答案)B.GuestescapeC.ProviderexitD.Escalationofprivileges答案解析:A.Thequestiondescribeshostescape.
OptionsBandCareotherrisksofoperatinginthecloud.OptionDcanleadtoAorB,butAisthemorespecificsituationandthereforethecorrectanswer.33.is/areprobablythemaincauseofvirtualizationsprawl.[單選題]A.MaliciousattackersB.LackofprovidercontrolsC.LackofcustomercontrolsD.Easeofuse(正確答案)答案解析:D.Becausemostcloudusersdon’tseedirectcostsincreatingnewVMinstances(thebillsusuallygotoasinglepointofcontactintheorganization,nottheuserortheuser’soffice),theymaytendtocreateadditionalVMsatasignificantrate,withoutrealizingtheattendantcost.Thisislargelybecauseitissoeasytodoandhasnoapparentcost,fromtheirperspective.
Alltheotheroptionsdonotcausevirtualizationsprawl.34.Sprawlismainlya(n)problem.[單選題]A.TechnicalB.ExternalC.Management(正確答案)D.Logical答案解析:C.Sprawlneedstobeaddressedfromamanagerialperspectivebecauseitiscausedbyalloweduseractions(usuallyinacompletelyauthorizedcapacity).
OptionsAandDmeanthesamethingandcouldbeconsideredascontributingtosprawlbecausethetechnologicalcapabilitiesofvirtualizationcreatetheeaseofusethatcancausesprawl.However,optionCisabetteranswer.
OptionBisincorrect;sprawloccurswithintheorganization.35.Whichofthefollowingrisksexistsinthetraditionalenvironmentbutisdramaticallyincreasedbymovingintothecloud?[單選題]A.PhysicalsecuritybreachesB.LossofutilitypowerC.FinancialupheavalD.Man-in-the-middleattacks(正確答案)答案解析:D.Becauseallcloudaccessisremoteaccess,theriskstodataintransitaredramaticallyheightenedinthecloud.
Theotheroptionsexistinboththetraditionalenvironmentandthecloudbutareprobablyactuallyreducedinthecloudbecausecloudproviderscanuseeconomiesofscaletoinvestinmeanstoreducethoserisksinwaysthatindividualorganizationswouldnotbeableto.36.Afundamentalaspectofsecurityprinciples,shouldbeimple-mentedinthecloudaswellasintraditionalenvironments.[單選題]A.ContinualuptimeB.Defenseindepth(正確答案)C.MultifactorauthenticationD.Separationofduties答案解析:B.Defenseindepth,orlayereddefense,isperhapsthemostfundamentalcharacteristicofallsecurityconcepts.
OptionsAandCaresecurityaspectsofsomeenvironments,andoptionAislikelyto
beanecessarytraitofmanagedcloudservices,buttheyarenotfundamentals—theyarespecifics.
OptionDisspecificallyanadministrativecontrol;thequestionislookingforafundamen-talaspectofsecurity.OptionBismoregeneral(itappliestoalltypesofsecurity,inallindustriesanduses)andthereforeisthecorrectchoiceforthisquestion.37.Fromasecurityperspective,automationofconfigurationaidsin[單選題]A.EnhancingperformanceB.Reducingpotentialattackvectors(正確答案)C.IncreasingeaseofuseofthesystemsD.Reducingneedforadministrativepersonnel答案解析:B.Asecurebaselineconfiguration,appliedandmaintainedautomatically,ensurestheoptimumsecurityfootprintwiththeleastattacksurface.
Alltheotheroptionsarebenefitsofautomatedconfigurationbutarenotspecificallysecu-rityenhancements.38.isthemostprevalentprotocolusedinidentityfederation.[單選題]A.HypertextTransferProtocol(HTTP)B.SecurityAssertionMarkupLanguage(SAML)(正確答案)C.FileTransferProtocol(FTP)D.WS-Federation答案解析:B.TheSecurityAssertionMarkupLanguage(SAML)isprobablythemostcommonprotocolbeingusedforidentityfederationatthemoment.
OptionsAandCarenotidentityfederationprotocols.
OptionDisafederationspecification,butitalsousesSAMLtokens.39.Ausersignsontoacloud-basedsocialmediaplatform.Inanotherbrowsertab,theuserfindsanarticleworthpostingtothesocialmediaplatform.Theuserclicksontheplat-form’siconlistedonthearticle’swebsite,andthearticleisautomaticallypostedtotheuser’saccountonthesocialmediaplatform.Thisisanexampleofwhat?[單選題]A.Singlesign-onB.InsecuredirectidentifiersC.Identityfederation(正確答案)D.Cross-sitescripting答案解析:C.Thisisaverypopularfunctionoffederatedidentity.
Singlesign-on(SSO)issimilartofederation,butitislimitedtoasingleorganization;fed-erationisbasicallySSOacrossmultipleorganizations.OptionAisincorrect.
OptionsBandDarethreatslistedintheOpenWebApplicationSecurityProject(OWASP)TopTen;theyareincorrect.40.Agroupofclinicsdecidestocreateanidentificationfederationfortheirusers(medicalprovidersandclinicians).Iftheyopttorevieweachother,forcompliancewithsecuritygovernanceandstandardstheyallfindacceptable,whatisthisfederationmodelcalled?[單選題]A.Cross-certification(正確答案)B.ProxyC.Singlesign-onD.Regulated答案解析:A.Thecross-certificationfederationmodelisalsoknownasaweboftrust.
Proxyisanothermodelforfederation,sooptionBisincorrect.
Singlesign-onissimilartofederation,butitislimitedtoasingleorganization;optionCisincorrect.
OptionDdoesnothaverelevanceinthiscontextandthereforeincorrectasananswer.41.Agroupofclinicsdecide
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 奉賢區(qū)羽毛球球場施工方案
- 水庫牧道及庫區(qū)清施工方案
- 長沙設(shè)備內(nèi)襯防腐施工方案
- 2025年中國搬運機器人產(chǎn)業(yè)深度分析、投資前景及發(fā)展趨勢預(yù)測報告
- 生態(tài)補償機制的建設(shè)與完善策略及實施路徑
- 中西通俗小說賞析知到課后答案智慧樹章節(jié)測試答案2025年春溫州理工學(xué)院
- 2025年電子金融相關(guān)設(shè)備項目建議書
- 數(shù)學(xué)高考備考講義第三章不等式35
- 燈條施工方案模板
- 2025年高三二輪專題復(fù)習(xí)學(xué)案地理(藝體生專用)第26講地區(qū)產(chǎn)業(yè)結(jié)構(gòu)變化與產(chǎn)業(yè)轉(zhuǎn)移
- 中考百日誓師大會-百日沖刺決戰(zhàn)中考-2024年中考百日誓師大會(課件)
- 非線粒體氧化體系講解課件
- 初中八年級語文課件-桃花源記 全國公開課一等獎
- 《無人機操控技術(shù)》教案全套 1.1 無人機概述 -6.2 自動機場操控
- ISO27001標(biāo)準(zhǔn)培訓(xùn)課件
- 《審核員培訓(xùn)教程》課件
- 《光催化技術(shù)》課件
- 辦公打印機的租賃合同范文
- 危大工程監(jiān)理巡視檢查用表
- 大埔縣生活垃圾填埋場應(yīng)急加固及滲濾液處理站擴容改造工程環(huán)境影響報告
- 餐飲行業(yè)儀容儀表標(biāo)準(zhǔn)規(guī)范
評論
0/150
提交評論