Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- http://searchcloudsecurity.techtarget.com/quiz/Quiz-Cloud-application-security-best-practice
- QUESTION 1
- Custom application development is generally done on which type of cloud service?
- a) Infrastructure-as-a-Service (IaaS)
- b) Software-as-a-Service (SaaS)
- c) Platform-as-a-Service (PaaS)
- d) Development-as-a-Service (DaaS)
- YOUR ANSWER - c) Platform-as-a-Service (PaaS)
- CORRECT ANSWER - Correct answer: C � Platform-as-a-Service is the best cloud service with which to conduct custom application development because the lower levels of the stack are managed by the provider.
- MORE INFORMATION:
- Learn whether a PaaS environment puts application data at risk.
- QUESTION 2
- In general, which type of cloud service provides the most areas of accountability for the customer?
- a) Platform-as-a-Service (PaaS)
- b) Security-as-a-Service
- c) Infrastructure-as-a-Service (IaaS)
- d) Software-as-a-Service (SaaS)
- YOUR ANSWER - c) Infrastructure-as-a-Service (IaaS)
- CORRECT ANSWER - Correct answer: C � IaaS offers the most accountability because the customer has control over the underlying operating systems/databases, etc. With PaaS, the provider manages those elements, and in SaaS the provider manages the OS and database, and, usually, the applications too.
- MORE INFORMATION:
- Learn about testing IaaS security.
- QUESTION 3
- Heroku, Azure, and BeanStalk are:
- a) Small, upstart cloud providers
- b) Messaging hygiene providers
- c) Platform-as-a-Service providers
- d) Reputation-based cloud firewall providers
- YOUR ANSWER - c) Platform-as-a-Service providers
- CORRECT ANSWER - Correct answer: C - Heroku, Azure, and BeanStalk are examples of established Platform-as-a-Service providers.
- MORE INFORMATION:
- Learn more about the security capabilities of PaaS providers.
- QUESTION 4
- Which of the following is/are not a well-known list of cloud controls?
- a) SSAE 16 (formerly SAS 70)
- b) CSA CCM
- c) ISO 27001:2005
- d) FedRAMP
- e) A and C
- f) B and D
- YOUR ANSWER - e) A and C
- CORRECT ANSWER - Correct answer: E � FedRAMP and the CSA CCM are listings of cloud-specific controls that can be used to assess cloud providers. Get reaction to the emerging FedRAMP cloud computing standards.
- QUESTION 5
- To find the best security-as-a-service offering for your organization:
- a) Ask the vendor what they recommend
- b) Assess your requirements, do a risk assessment and a cost/benefit analysis of the options
- c) Find the cheapest monthly option and use whatever is offered with that service
- d) Ask your peers and do exactly what they're doing
- YOUR ANSWER - b) Assess your requirements, do a risk assessment and a cost/benefit analysis of the options
- CORRECT ANSWER - Correct answer: B - Although the other options can be used as input during the decision-making process, the most important considerations are your own requirements and risk analysis. Check out these guidelines for evaluating cloud computing risk.
- QUESTION 6
- Which of the following is not a common security-as-a-service offering?
- a) Mail hygiene
- b) Vulnerability scanning
- c) Streaming CDNs
- d) Cloud storage/backup
- e) Web hygiene
- f) Log aggregation/SIM
- YOUR ANSWER - c) Streaming CDNs
- CORRECT ANSWER - Correct answer: C � Streaming CDNs are not a common security-as-a-service offering.
- MORE INFORMATION:
- Learn why more companies are considering SIEM in the cloud.
- QUESTION 7
- Using a cloud provider for security services is always:
- a) Cheaper than doing it on-premise
- b) More secure than doing it on-premise
- c) The right thing to do
- d) A way to impress your boss
- e) It depends
- YOUR ANSWER - e) It depends
- CORRECT ANSWER - Correct answer: E � The benefits of using cloud-based security services will vary from one organization to the next.
- MORE INFORMATION:
- Learn about a study that showed cloud provider security is better than on-premise security.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement