CompTIA Security + Cert Prep 6 Cloud
Sec. Design and Imp (Answered)
Updated Fall 2024/2025.
cloud computing
delivers computing resources to a remote customer over a network
-ubiquitous, convenient
-on demand network access
-networks, servers, storage, applications, and services
Cloud Service Provider (CSP)
A company that offers cloud-based network services, infrastructure, or business applications.
- build and maintain service
cloud customers
purchases cloud computing services from one of more cloud service providers
cloud service partner
provide add on services to cloud computing
-third party companies
Cloud Access Security Broker (CASB)
A software tool or service that enforces cloud-based security requirements. It is placed between the
organization's resources and the cloud, monitors all network traffic, and can enforce security policies.
-IAM services
horizontal scaling
Adds more servers to the pool to meet increased demand
vertical scaling
adds more resources (CPU or Memory) to existing servers to meet increased demands
elasticity
expanding or contracting quickly
-add or remove servers
measured service
paying for only what you consume
resource pooling
, Cloud computing services to multiple customers that are hosted on shared physical resources and
dynamically allocated to meet customer demand.
Managed service provider (MSP)
a company that remotely manages a customer's IT infrastructure
managed security service provider (MSSP)
A company that monitors security infrastructure and system logs, manages firewalls or networks, and
identity and access management
-also referred to as Security as a service (SECaaS)
Network-Based CASB
Broker intercepts traffic between the user and the cloud service, monitoring for security issues. Broker
can block requests.
API-based CASB
the broker queries the cloud service via API
-broker may not be able to block requests, depending upon API capabilities
Virtualization
host machines run on physical hardware
host machines provide services to several virtual machines
the hypervisor tricks each guest into thinking its running dedicated hardware
Type 1 hypervisor
Also known as a bare metal hypervisor it is a software program that acts as an operating system and also
provides the ability to perform virtualization of other operating systems using the same computer.
-hypervisor runs directly on top of the hardware
-most common found in data centers
Type 2 hypervisor
A software program that sits on top of an existing operating system and provides the ability to host
multiple virtual operating systems on the same computer at the same time.
ex. VirtualBox
VM escape attack
An attack that allows an attacker to access the host system from within the virtual system
VM Sprawl
occurs when an organization has many VMs that aren't managed properly
Application Virtualization
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller ACADEMICAIDSTORE. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.49. You're not tied to anything after your purchase.