Font size
WorksheetsMod 11 Sec+ 8e
Total questions: 34
Worksheet time: 17mins
Which of the following statements most accurately describes characteristics of cloud computing? Select two.
They reduce the cost of CapEx by shifting them to OpEx.
It provides peace of mind knowing exactly where your data resides.
Computing resources can be increased or decreased quickly to meet changing demands.
Increasing computing resources require minimal human interaction from service providers.
A potential client wants to migrate some of their services to the cloud but is concerned about failover capabilities. What will the sales engineer from the cloud provider most likely say to help ease the client's concern?
The cloud company will reserve additional computing resources for immediate availability.
The client can pay a little extra every month to ensure excess capacity can be provisioned.
If there is a server failure, the client will be immediately contacted for further instructions.
If there is a server failure, services will be moved to other servers at no additional cost.
You are a cloud sales engineer working with an institution that needs to comply with strict federal regulations to avoid being levied very hefty fines. What type of cloud offering are you most likely to recommend?
A public cloud
A hybrid cloud
A private cloud
A community cloud
Diana is not very tech savvy but is a marketing genius. She signs a deal with a cloud contractor who will help her set up an online retail store selling rare items. On what type of cloud will her website most likely be hosted?
A public cloud because the cloud services are available to everyone.
A hybrid cloud because some elements need a higher degree of security.
A private cloud to ensure all transactions use encryption and secure authentication.
A community cloud because the rare items she sells have an exclusive community of followers.
Your company asks you to be the project lead in establishing a private cloud. Which of the following are most likely to be true? Select two.
You will use a cloud provider with tight integration to ensure outside entities cannot connect.
You will create a private network and isolate it from all the available cloud service providers.
You will create a network with no connectivity to ensure a high degree of privacy and security.
You expect your company to purchase and maintain all the required hardware and software.
You will use proprietary software on dedicated servers and storage from a cloud provider.
An industrial plant has a series of Internet of Things devices that connect to a nearby wireless system. The system will process the collected data, store it, and send it off to the cloud. From a computing location perspective, what type of model is assumed in this scenario?
Fog
Cloud
Edge
Hybrid
This scenario relates to computing that is performed at or very near to the source of data (edge) instead of relying on the cloud or on-premises for processing.
Edge
Cloud
Off-premises
A programming hobbyist uses a cloud provider to create an online app to back up his CD collection. As soon as he launches the app, it creates an online backup in the form of an ISO image, creates separate MP3 files for each song, and downloads them to a specific folder. What type of computing does this most likely resemble?
On-premises
Edge
Cloud
Fog
Off-premises
A company is using resources on a server to host an application in a Software as a Service (SaaS) environment. Which of the following best describes the type of architecture being employed?
Serverless infrastructure
Transit gateway
Thick client
Thin client
SWG
Various departments in a large organization have been using computing and storage resources from AWS in an uncoordinated fashion. To manage their cloud resources more efficiently, they would like to adopt an approach that is more consolidated and streamlined. Which of the following would you recommend?
Cloud-native microservices
Transit gateway
Direct-connect portal
Secure web gateway
A university is locally managing the learning management system they use for students on a few clustered servers. They are exploring cloud solutions to relieve some of the burden related to managing the servers. Which of the following implementations would help them satisfy their requirement?
IaaS
SaaS
PaaS
XaaS
DaaS
A small team of innovative engineers are organizing a company to research and develop unconventional computing and networking modes of operation. Since they have limited funds for hardware, they will initially use a cloud provider. What type of cloud platform are they most likely to use?
IaaS
SaaS
PaaS
XaaS
DaaS
Infrastructure as a Service (IaaS) provides unlimited raw computing, storage, and network resources that the enterprise can use to build their own virtual infrastructure in the cloud. The number of central processing units and their speed, the amount of memory, the volume of storage, and the desired virtual networking resources like routers and switches can all be arranged to create the necessary virtual infrastructure.
PaaS
SaaS
XaaS
CaaS
IaaS
Company A bought out Company B because they are certain they can dramatically capitalize on their software portfolio. Company B sees many opportunities in porting a good number of their offerings to the cloud using a cloud-native format. What are some of the benefits Company B anticipates by porting the software? Select two.
The monolithic nature of cloud-based apps allows microservices to be easily developed.
Software teams can use a variety of programming languages when rewriting the code.
Cloud-based apps are well suited for microservices APIs and RESTful APIs.
The cloud-based apps will be accessible to a larger variety of customers.
It is easier to maintain a comprehensive database versus a few smaller ones.
In this architecture, software code can be updated more easily with new features and functionality added without rewriting the entire application. What framework, model, or architecture does this statement describe? Select two.
Three-tier
Monolithic
Cloud-native
Microservices
How does a cloud firewall differ from one installed and implemented using a physical security appliance?
Cloud firewalls require no physical entity whatsoever.
Cloud firewalls may cost more in the long run.
Cloud firewalls are implemented virtually just on the other side of the edge router.
Cloud firewall expenses are factored into the CapEx chart of accounts for accounting purposes.
As a cloud specialist, you are asked to set up a system that, among other capabilities, can analyze traffic that is encrypted using SSL. What type of device are you most likely to deploy?
CASB
SASE
CSWG
SWG
In the statements they wrote, which of the following are NOT true? Select two.
The security of applications running in the cloud is the responsibility of the cloud provider.
If we develop an app with built-in security, its native instantiation will be sufficiently secure.
Installing a CASB ensures the security policies of the enterprise extend to its data in the cloud.
Installing a SWG automatically combines several security features into a single product.
A large organization uses a cloud provider with a security model that incorporates a variety of technologies. Their goal is to ensure predefined security policies are applied when their data or applications are accessed. In addition, they want to continue monitoring security risks when users or devices are connected. What type of model are they using to help ensure access to their digital assets is secure?
MSP
CASB
SASE
SWG
A company was convinced their cloud implementation was very secure. However, a security audit conducted by a third-party cloud security company discovered a vulnerability. Which of the following could have contributed to, or explains, the vulnerability?
Since they didn't have physical access, they could not fully test their IaaS implementation.
The vulnerability was most likely due to an oversight by the cloud provider.
They missed an operating system patch in the SaaS implementation they were running.
They failed to clearly understand the responsibility matrix.
Which of the following most accurately describes the relationship between the Open Systems Interconnection (OSI) model used to describe a traditional network and the cloud?
The OSI model can easily be used or adapted to map out the desired cloud security profile.
Cloud providers secure the lower layers while cloud users secure the upper layers.
The OSI model is not very useful because cloud assets are virtualized.
Cloud implementations should use the cloud-specific OSI model.
True
False
The OSI model is no longer as useful with cloud computing.
Tanvi is responsible for applying and enforcing mitigation controls to help secure the cloud implementation her company is about to deploy. What areas of cloud computing is she most likely to be concerned with? Select three.
Storage
Compute
Network
Operating systems
Applications
A government agency agrees to include a contractual clause that enables third parties to assess security control of cloud providers. Why are they most likely to include such a clause?
They want to be authenticated as being in compliance.
To allow third-party contractors to apply security controls.
They want to ensure they will be able to renew their contract.
It allows them to use an independent party to confirm their implementation is secure.
A company has been managing their data center for years. As the company has grown, so has their need for additional hardware. They've decided to migrate to the cloud but need a solution that can withstand natural disasters. Which of the following best identifies the feature of cloud providers that can furnish this capability?
Failover capabilities
Redundancy
Clustering
Zones
A company has ported their software to the cloud using a cloud-native format. The components of the application were implemented using a collection of microservices. Which of the following best describes what the company should do to ensure the microservices are able to access each other securely?
Encrypt communication between microservices.
Implement secrets management.
Enable secret-specific versioning.
Use an interprocess password manager.
You configure a collection of cloud-based virtual machines (VMs) that should be logically separated from other systems in your cloud configuration. What type of control can you implement to help realize this end?
Segmented resource allocation
Instance awareness
Security group
Use security groups to segment the different computing resources into logical groupings that form network perimeters.
VPC endpoint
Security group
Network ACL
VPC endpoint
Yara is responsible for managing the hybrid cloud posture her company has adopted. Which of the following practices is Yara most likely to help enforce? Select two.
Audit configurations manually to ensure they align.
Inspect encrypted traffic.
Enforce zero-trust on servers.
Run scans to identify weak points.
Which of the following statements are true regarding containers and VMs? Select three.
A Type I hypervisor is a bare metal hypervisor.
Containers share the host OS kernel.
VMs provide full isolation from the host OS.
Containers are more lightweight than VMs.
In an SDN you need to configure the entity responsible for routing and security checks. Which component are you going to be configuring?
Control plane
Data plane
Control logic
Flow tables
Switching logic
A large corporation with offices and branch sites throughout the world needs the flexibility of being able to securely handle different kinds of traffic and conditions between sites in real time. Which of the following technologies is most likely to offer the best solution?
SDN
SDV
SD-VLAN
SD-WAN
SD-LAN
Jelvin is working for an organization that is committed to developing software in which critical security functions can be automated and not require manual intervention. Which of the following enables this capability?
SDV
SDS
SDN
SDSec
SDSW
Which of the following best describes what should be used to help secure VMs and/or containers? Select two.
ACLs
SELinux
Nonprivileged user accounts to manage container-based processes
Secure administrator user accounts to manage container-based processes
Physical security devices between servers running multiple virtual machines
