Deck 5: Network Access Control and Cloud Security

ملء الشاشة (f)
exit full mode
سؤال
Data must be secured while at rest, in transit, and in use, and access to the data must be controlled.
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
In using cloud infrastructures, the client necessarily cedes control to the CP on a number of issues that may affect security.
سؤال
The __________ is an Internet protocol that enables dynamic allocation of IP addresses to hosts

A)VLAN
B)IEEE 802.1X
C)EAPS
D)DHCP
سؤال
Cloud computing gives you the ability to expand and reduce resources according to your specific service requirement.
سؤال
The threat of data compromise decreases in the cloud.
سؤال
The NIST cloud computing reference architecture focuses on the requirements of "what" cloud services provide, not a "how to" design solution and implementation.
سؤال
The Extensible Authentication Protocol supports multiple authentication methods.
سؤال
___________ is an umbrella term for managing access to a network

A)NAS
B)ARC
C)NAC
D)RAS
سؤال
For many clients, the most devastating impact from a security breach is the loss or leakage of data.
سؤال
_________ is a client computer that is attempting to access a network

A)EAP peer
B)PSK
C)NAC
D)RAS
سؤال
The _________ is the node that is attempting to access the network and may be any device that is managed by the network access control system

A)AR
B)RAS
C)IP
D)PS
سؤال
Network access control authenticates users logging into the network and determines what data they can access and actions they can perform.
سؤال
The cloud provider in a private cloud infrastructure is responsible for both the infrastructure and the control.
سؤال
Access requestors are also referred to as clients.
سؤال
A network access server does not include its own authentication services.
سؤال
A cloud broker is useful when cloud services are too complex for a cloud consumer to easily manage.
سؤال
There is a decreasing trend in organizations to move information technology operations to a cloud computing infrastructure.
سؤال
VLANs are common NAC enforcement methods.
سؤال
The __________ determines what access should be granted

A)authentication server
B)policy server
C)supplicant
D)access requestor
سؤال
EAPOL operates at the network layers and makes use of an IEEE 802 LAN, such as Ethernet or Wi-Fi, at the link level.
سؤال
___________ includes people, processes, and systems that are used to manage access to enterprise resources by assuring that the identity of an entity is verified, and then granting the correct level of access based on this assured identity.
سؤال
A ________ is a person, organization, or entity responsible for making a service available to interested parties

A)cloud broker
B)cloud auditor
C)cloud provider
D)cloud carrier
سؤال
With a ________ infrastructure, the cloud infrastructure is a composition of two or more clouds that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability.
سؤال
__________ methods are the actions that are applied to ARs to regulate access to the enterprise network.
سؤال
A _________ is a person or organization that maintains a business relationship with, and uses service from, cloud providers

A)cloud auditor
B)cloud broker
C)cloud carrier
D)cloud consumer
سؤال
With a _________ infrastructure, the cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services

A)hybrid cloud
B)private cloud C public cloud
D)community cloud
سؤال
_________ saves the complexity of software installation, maintenance, upgrades, and patches

A)IaaS
B)SaaS
C)EAP
D)DHCP
سؤال
An __________ is a server computer that negotiates the use of a specific EAP method with an EAP peer, validates the EAP peer's credentials, and authorizes access to the network.
سؤال
_________ is the provision of security applications and services via the cloud either to cloud-based infrastructure and software or from the cloud to the customers' on-premise systems

A)IaaS
B)PaaS
C)SaaS
D)SecaaS
سؤال
With a _________ infrastructure, the cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns

A)community cloud
B)public cloud
C)private cloud
D)hybrid cloud
سؤال
A _________ in an intermediary that provides connectivity and transport of cloud services from CP's to cloud consumers.
سؤال
A _________ is an entity at one end of a point-to-point LAN segment that seeks to be authenticated by an autheticator attached to the other end of that link.
سؤال
In effect, ________ is an operating system in the cloud

A)IEEE 802.1X
B)PaaS
C)IaaS
D)DHCP
سؤال
The ___________ functions as an access control point for users in remote locations connecting to an enterprise's internal network.
سؤال
A ________ is a party that can conduct independent assessment of cloud service, information sytem operations, performance, and security of the cloud implementation

A)cloud auditor
B)cloud carrier
C)cloud broker
D)all of the above
سؤال
Broad network access, measured service, resource pooling, and rapid elasticity are essential characteristics of ___________

A)PaaS
B)network access control
C)cloud computing
D)EAP-TLS
سؤال
NIST defines three service models, which can be viewed as nested service alternatives: software as a service, platform as a service, and _________ as a service.
سؤال
_________ enables customers to combine basic computing services, such as number crunching and data storage, to build highly adaptable computer systems

A)IaaS
B)EAP peer
C)CP
D)SaaS
سؤال
A __________ provides a form of NAC by allowing or denying network traffic between an enterprise host and an external user.
سؤال
_________ is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.
سؤال
An _________ is an access point or NAS that requires EAP authentication prior to granting access to a network.
سؤال
____________ is an EAP method for mutual authentication and session key derivation using a Pre-Shared Key.
سؤال
__________ are third party audits of cloud services.
سؤال
The Cloud Security Alliance defines _______ as the provision of security applications and services via the cloud either to cloud-based infrastructure and software or from the cloud to the customers' on-premise systems.
سؤال
_________ defines how the TLS protocol can be encapsulated in EAP messages.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/45
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 5: Network Access Control and Cloud Security
1
Data must be secured while at rest, in transit, and in use, and access to the data must be controlled.
True
2
In using cloud infrastructures, the client necessarily cedes control to the CP on a number of issues that may affect security.
True
3
The __________ is an Internet protocol that enables dynamic allocation of IP addresses to hosts

A)VLAN
B)IEEE 802.1X
C)EAPS
D)DHCP
D
4
Cloud computing gives you the ability to expand and reduce resources according to your specific service requirement.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
5
The threat of data compromise decreases in the cloud.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
6
The NIST cloud computing reference architecture focuses on the requirements of "what" cloud services provide, not a "how to" design solution and implementation.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
7
The Extensible Authentication Protocol supports multiple authentication methods.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
8
___________ is an umbrella term for managing access to a network

A)NAS
B)ARC
C)NAC
D)RAS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
9
For many clients, the most devastating impact from a security breach is the loss or leakage of data.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
10
_________ is a client computer that is attempting to access a network

A)EAP peer
B)PSK
C)NAC
D)RAS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
11
The _________ is the node that is attempting to access the network and may be any device that is managed by the network access control system

A)AR
B)RAS
C)IP
D)PS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
12
Network access control authenticates users logging into the network and determines what data they can access and actions they can perform.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
13
The cloud provider in a private cloud infrastructure is responsible for both the infrastructure and the control.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
14
Access requestors are also referred to as clients.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
15
A network access server does not include its own authentication services.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
16
A cloud broker is useful when cloud services are too complex for a cloud consumer to easily manage.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
17
There is a decreasing trend in organizations to move information technology operations to a cloud computing infrastructure.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
18
VLANs are common NAC enforcement methods.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
19
The __________ determines what access should be granted

A)authentication server
B)policy server
C)supplicant
D)access requestor
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
20
EAPOL operates at the network layers and makes use of an IEEE 802 LAN, such as Ethernet or Wi-Fi, at the link level.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
21
___________ includes people, processes, and systems that are used to manage access to enterprise resources by assuring that the identity of an entity is verified, and then granting the correct level of access based on this assured identity.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
22
A ________ is a person, organization, or entity responsible for making a service available to interested parties

A)cloud broker
B)cloud auditor
C)cloud provider
D)cloud carrier
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
23
With a ________ infrastructure, the cloud infrastructure is a composition of two or more clouds that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
24
__________ methods are the actions that are applied to ARs to regulate access to the enterprise network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
25
A _________ is a person or organization that maintains a business relationship with, and uses service from, cloud providers

A)cloud auditor
B)cloud broker
C)cloud carrier
D)cloud consumer
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
26
With a _________ infrastructure, the cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services

A)hybrid cloud
B)private cloud C public cloud
D)community cloud
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
27
_________ saves the complexity of software installation, maintenance, upgrades, and patches

A)IaaS
B)SaaS
C)EAP
D)DHCP
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
28
An __________ is a server computer that negotiates the use of a specific EAP method with an EAP peer, validates the EAP peer's credentials, and authorizes access to the network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
29
_________ is the provision of security applications and services via the cloud either to cloud-based infrastructure and software or from the cloud to the customers' on-premise systems

A)IaaS
B)PaaS
C)SaaS
D)SecaaS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
30
With a _________ infrastructure, the cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns

A)community cloud
B)public cloud
C)private cloud
D)hybrid cloud
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
31
A _________ in an intermediary that provides connectivity and transport of cloud services from CP's to cloud consumers.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
32
A _________ is an entity at one end of a point-to-point LAN segment that seeks to be authenticated by an autheticator attached to the other end of that link.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
33
In effect, ________ is an operating system in the cloud

A)IEEE 802.1X
B)PaaS
C)IaaS
D)DHCP
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
34
The ___________ functions as an access control point for users in remote locations connecting to an enterprise's internal network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
35
A ________ is a party that can conduct independent assessment of cloud service, information sytem operations, performance, and security of the cloud implementation

A)cloud auditor
B)cloud carrier
C)cloud broker
D)all of the above
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
36
Broad network access, measured service, resource pooling, and rapid elasticity are essential characteristics of ___________

A)PaaS
B)network access control
C)cloud computing
D)EAP-TLS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
37
NIST defines three service models, which can be viewed as nested service alternatives: software as a service, platform as a service, and _________ as a service.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
38
_________ enables customers to combine basic computing services, such as number crunching and data storage, to build highly adaptable computer systems

A)IaaS
B)EAP peer
C)CP
D)SaaS
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
39
A __________ provides a form of NAC by allowing or denying network traffic between an enterprise host and an external user.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
40
_________ is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
41
An _________ is an access point or NAS that requires EAP authentication prior to granting access to a network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
42
____________ is an EAP method for mutual authentication and session key derivation using a Pre-Shared Key.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
43
__________ are third party audits of cloud services.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
44
The Cloud Security Alliance defines _______ as the provision of security applications and services via the cloud either to cloud-based infrastructure and software or from the cloud to the customers' on-premise systems.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
45
_________ defines how the TLS protocol can be encapsulated in EAP messages.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.