WorksheetsEHE Module 11: Cloud Computing
Total questions: 67
Worksheet time: 34mins
What is cloud computing primarily described as?
On-demand delivery of IT capabilities over a network
A physical storage solution for data
A type of hardware used in data centers
A software development methodology
Which of the following is a characteristic of cloud computing?
Limited network access
Rapid elasticity
Manual management
Fixed storage
What is a limitation of cloud computing?
Unlimited control for organizations
No dependence on network connections
Proneness to outages and technical issues
Guaranteed security and privacy
Which type of cloud computing service provides virtual machines and abstracted hardware?
Platform-as-a-Service (PaaS)
Software-as-a-Service (SaaS)
Infrastructure-as-a-Service (IaaS)
Security-as-a-Service (SECaaS)
What does Platform-as-a-Service (PaaS) offer?
Virtual machines and hardware
Development tools and deployment platforms
Web-based office applications
Identity management services
Which service is an example of Software-as-a-Service (SaaS)?
Amazon EC2
Google App Engine
Google Docs
OneLogin
What does Identity-as-a-Service (IDaaS) provide?
Container management
Virtual machines
Identity and access management services
Web-based applications
Which of the following is an example of Container-as-a-Service (CaaS)?
Microsoft Azure
Google Kubernetes Engine (GKE)
Salesforce CRM
Okta
What is Function-as-a-Service (FaaS) primarily used for?
Developing and managing microservices
Providing hardware infrastructure
Offering customer support services
Managing network security
Which cloud deployment model is operated for a single organization only?
Public Cloud
Private Cloud
Community Cloud
Hybrid Cloud
What does the NIST cloud computing reference architecture define?
Five major actors
Three cloud layers
Two deployment models
Four service providers
Which layer in cloud storage architecture is accessed by the end user?
Front-end
Middleware
Back-end
Hardware
Which of the following is a cloud service provider?
Microsoft Azure
Oracle Database
Cisco Systems
Dell Technologies
What is a container in the context of container technology?
A package of an application/software including all its dependencies
A virtual machine running multiple operating systems
A physical server used for storage
A network device for routing data
Which of the following is a feature of container technology?
Portability and consistency
High hardware requirements
Limited scalability
Complex setup process
What is the role of Tier-4 in container technology architecture?
Developer machines for image creation
Orchestrators for transforming images into containers
Registries for storing images
Hosts for operating and managing containers
Which of the following is an advantage of using containers?
Increased complexity
Easy management of isolated applications
Lack of staff expertise
Questionable container performance
What is a disadvantage of container technology?
Increased application portability
Increased vulnerability owing to shared resources
Scalable resources
Easy testing and debugging
What does virtualization allow in the context of containers vs. virtual machines?
Running multiple operating systems on a single physical system
Running a single application on multiple servers
Isolating applications from each other
Increasing the physical size of servers
What is a key characteristic of virtual machines compared to containers?
Heavyweight
Lightweight
Share a single host operating system
OS-based virtualization
Which of the following is true about containers?
Run on independent operating systems
Hardware-based virtualization
Process-level isolation, partially secured
Slower provisioning
What is Docker primarily used for?
Developing, packaging, and running applications in containers
Creating virtual machines
Managing hardware resources
Developing operating systems
What does the Container Network Model (CNM) provide?
Application portability across heterogeneous infrastructures
Hardware-based virtualization
Independent operating systems
Slower provisioning
What is the purpose of container orchestration?
Managing the lifecycles of software containers
Creating virtual machines
Developing operating systems
Running applications in containers
What is Kubernetes primarily used for?
Managing containerized applications and microservices
Developing mobile applications
Designing user interfaces
Creating video games
Which feature of Kubernetes allows a service to be discovered via a DNS name or IP address?
Load balancing
Service discovery
Automated rollouts
Secret management
What does Kubernetes automate in terms of container management?
Manual coding
Creating new containers and destroying existing ones
Designing graphics
Writing documentation
How does Kubernetes handle heavy traffic to a container?
It shuts down the container
It performs load balancing
It increases the container size
It ignores the traffic
What is a key difference between Kubernetes and Docker?
Kubernetes is for mobile apps, Docker is for web apps
Kubernetes manages clusters, Docker runs on a single host
Docker is for databases, Kubernetes is for networking
Docker is for gaming, Kubernetes is for AI
What is Kubernetes primarily used for in relation to Docker hosts?
Managing databases
Managing Docker hosts on multiple operating systems
Creating virtual machines
Developing web applications
Which programming language is used to build both Docker and Kubernetes?
Python
Java
Go
Ruby
What is a major security challenge associated with containers?
Limited scalability
Inflow of vulnerable source code
High cost of deployment
Slow execution speed
What does a large attack surface in container security imply?
Fewer vulnerabilities
Easier detection of threats
Increased difficulty in detecting vulnerabilities
Reduced abstraction
Which container platform is associated with Amazon?
Docker
Red Hat OpenShift
Amazon Elastic Container Service (ECS)
Portainer
What is Kubernetes primarily used for?
Data storage
Container orchestration
Network security
User authentication
Which cloud service is provided by Amazon for Kubernetes?
Google Kubernetes Engine
IBM Cloud Kubernetes Service
Amazon Elastic Kubernetes Service
Docker Kubernetes Service
What is a major risk associated with using public cloud services for data?
Increased data accountability
Enhanced data recoverability
Loss of data accountability and control
Improved data security
What challenge does User Identity Federation present in cloud computing?
Simplifies user management
Reduces the number of user IDs
Complicates the management of multiple user IDs and credentials
Enhances user control over data
Why is regulatory compliance complex in cloud computing?
Uniform laws across countries
Lack of transparency and different regulatory laws
Simplified data security measures
Consistent data protection standards
What risk does the use of social websites pose to personal data?
Enhanced data privacy
Data stored locally
Mining of user data for secondary usage
Improved data security
What is the concept of multi-tenancy in cloud technology?
Exclusive resource allocation
Sharing resources among multiple clients
Single client resource usage
Dedicated server usage
What is a challenge faced by law enforcement agencies when dealing with forensic recovery in cloud environments?
Centralized storage of logs
Distributed storage of logs across multiple countries
Lack of event logs
Single host storage
Why should configuration baselines of infrastructure comply with industry best practices?
To reduce costs
To ensure faster network speeds
Due to the constant risk of malicious actions
To increase storage capacity
What risk is increased by using non-production environments?
Faster application development
Unauthorized access and information disclosure
Improved user interface
Enhanced data encryption
Which of the following is a cloud computing threat related to time management?
Insecure Interfaces and APIs
Unsynchronized System Clocks
Shared Technology Issues
Natural Disasters
What can misconfiguration of infrastructure allow in a cloud environment?
Faster data processing
Network scanning for vulnerable applications
Increased storage capacity
Enhanced user experience
What is a potential risk associated with cloud computing that involves unauthorized use of a victim's computer to mine digital currency?
Cloud Hopper Attack
Cloud Cryptojacking
Man-in-the-Cloud Attack
Wrapping Attack
Which type of cloud attack involves placing a malicious virtual machine near a target cloud server to launch a side-channel attack?
Cloud Hopper Attack
Wrapping Attack
Side-Channel Attack
Man-in-the-Cloud Attack
What is the main goal of a Cloud Hopper Attack?
To mine digital currency
To compromise accounts of staff or cloud service firms
To duplicate the body of a message
To steal cryptographic keys
In a Man-in-the-Cloud (MITC) attack, what does the attacker steal to gain access to the victim's files?
Encryption keys
Synchronization token
Passwords
Digital certificates
What is a key characteristic of cryptojacking attacks?
They are easily detectable.
They involve both external attackers and rogue insiders.
They only target personal computers.
They are not financially motivated.
What is the purpose of the malicious backdoor in a Cloudborne attack?
To enhance server performance.
To bypass security mechanisms and steal data.
To improve cloud storage capacity.
To provide free cloud services.
What is the function of the lazys3 tool?
To encrypt AWS S3 buckets.
To brute-force AWS S3 buckets using different permutations.
To monitor AWS S3 bucket traffic.
To delete AWS S3 buckets.
Which of the following is a cloud attack countermeasure?
Share user credentials among services.
Enforce data protection, backup, and retention mechanisms.
Disable security checkpoints.
Ignore public domain blacklists.
What is the purpose of the Nimbostratus tool?
To enhance cloud storage speed.
To fingerprint and exploit Amazon cloud infrastructures.
To provide free cloud services.
To encrypt cloud data.
What is a recommended practice to ensure cloud security?
Use single-factor authentication
Avoid regular security checks
Leverage strong two-factor authentication techniques
Disclose all security details to the public
What should be implemented to prevent side-channel attacks in cloud computing?
Use a single firewall
Implement a virtual firewall in the cloud server back-end
Disable encryption
Allow unrestricted access to all VMs
Which method is used to detect SOAP messages in wrapping attack countermeasures?
Use JSON validation
Use XML schema validation
Use HTML validation
Use plain text validation
What is a countermeasure against MITC attacks?
Use outdated antivirus software
Implement cloud access security broker (CASB)
Disable email security gateways
Ignore token expiration policies
What is a key countermeasure against cloud hopper attacks?
Implement single-factor authentication
Implement multi-factor authentication
Avoid coordination between customers and CSPs
Store encryption keys within the same cloud service
What is a recommended practice for securing access to cloud servers?
Use simple passwords
Use encrypted SSH key pairs
Share passwords with team members
Disable firewalls
Which tool provides an end-to-end IT security solution with visibility across all IT assets?
CloudPassage Halo
CipherCloud
Qualys Cloud Platform
Netskope Security Cloud
What should CSPs do to prevent Cloudborne attacks?
Ignore firmware updates
Use outdated software
Keep the firmware up-to-date
Disable security features
Which of the following is a countermeasure against cloud cryptojacking?
Use outdated antivirus tools
Implement CoinBlocker URL
Disable endpoint security
Share data copies with everyone
What is a key benefit of using container orchestration tools like Kubernetes?
Increased hardware costs
Complex configuration management
Manual scaling of applications
Automated deployment and scaling
Which of the following best describes the concept of Infrastructure as Code (IaC)?
Using physical hardware for deployment
Developing applications without code
Automating infrastructure setup using code
Manual server configuration
What is a common challenge when managing microservices in a cloud environment?
Increased monolithic architecture
Complexity in service communication
Reduced scalability
Limited resource allocation
