



Study with the several resources on Docsity
Earn points by helping other students or get them with a premium plan
Prepare for your exams
Study with the several resources on Docsity
Earn points to download
Earn points by helping other students or get them with a premium plan
WGU C838 Managing Cloud Security
Typology: Exams
1 / 6
This page cannot be seen from the preview
Don't miss anything!




Data Lifecycle - CORRECT ANSWER โโโ Create, Store, Use, Share, Archive and Destroy SDLC - CORRECT ANSWER โโโ Define, Design, Develop, Test, Secure Operations and Disposal FIPS 140-2 - CORRECT ANSWER โโโ NIST Document, describes process for accrediting cryptosystems for US Federal use. NIST 800-53 - CORRECT ANSWER โโโ Assures appropriate security requirements for US GOV information management systems. TCI - CORRECT ANSWER โโโ Trusted Cloud Initiative reference model, Guide for CSP's to create holistic architecture of DC. Cloud customers can use. Copyright - CORRECT ANSWER โโโ Legal protections for expressions of ideas. Movie, song, etc. -Expires 70 years from authors death or 120 years after first publication of work. Trademarks - CORRECT ANSWER โโโ Representations of an organization. Ex: Nike. -Must register w/ jurisdiction -R symbol represents registration w/ USPTO -TM symbol represents registration w/ State Office -Valid as long as organization uses it Patents - CORRECT ANSWER โโโ USPTO, intellectual property (inventions, processes), -Patents last 20 years from publication WIPO - CORRECT ANSWER โโโ World Intellectual Property Organization, -152 countries ITAR - CORRECT ANSWER โโโ International Traffic in Arms Regulations, -US State Department -Prohibitions on defense exports including cryptosystems EAR - CORRECT ANSWER โโโ Export Administration Regulations, -US Department of Commerce -Prohibits export of dual use products (civilian/Military) Wassenaar Agreement - CORRECT ANSWER โโโ -Not a binding legal contract
-41 countries -Let each other know about arms shipments to nonmember nations SOC 1 - CORRECT ANSWER โโโ Financial, non IT related SOC report SOC 2 - CORRECT ANSWER โโโ SOC 2 TYPE 1: Design of controls in point of time -Useless SOC 2 - CORRECT ANSWER โโโ SOC 2 Type 2: USEFUL IT Security related, How security controls are designed over a range of time SOC 3 - CORRECT ANSWER โโโ Public document meant to be shared as an attestation of a CSP's DC by a 3rd party ISO 27034-1 - CORRECT ANSWER โโโ Standards for Secure Application Development -Overview of application security REST API - CORRECT ANSWER โโโ Representational State Transfer, -Low processing overhead -simple URLs URIs -Language agnostic -Scalable -Output CSV or JSON Works well when: -Bandwidth is limited -Stateless operations -Caching is required SOAP - CORRECT ANSWER โโโ Simple Object Access Protocol, -Via SMTP, FTP and HTTP -Standards based -XML -Highly tolerant of errors -Built in error handling -Slower Works well when: -Asynchronous processing
Admin: FDIC Federal deposit Insurance Corporation FFIEC Enforcer: FDIC/DFI SOX - CORRECT ANSWER โโโ Sarbanes-Oxley Act -Increase corporate trading transparency to prevent fraud -CIA: Confidentiality, Integrity and Availability Admin: SEC Enforcer: SEC HIPPA - CORRECT ANSWER โโโ Health Insurance Portability and Accountability Act -ePHI electronic and nonelectronic health records confidentiality Admin: DHHS Enforcer: OCR Office for Civil Rights FERPA - CORRECT ANSWER โโโ Family Educational Rights and Privacy Act -prevent student data disclosure Admin: Department of Education Enforcer: Department of Education Family Policy Compliance Office DMCA - CORRECT ANSWER โโโ Digital Millennium Copyright Act
-Certification given to CSPs for GOV use of cloud systems (Agencies/Gov Contractors) GDPR - CORRECT ANSWER โโโ General Data Protection Regulation -EU default data protection -Notice, choice, purpose, access, integrity, security and enforcement -Can also utilize the Right to be Forgotten Privacy Shield - CORRECT ANSWER โโโ For orgs in US to be allowed to collect EU citizen's data. -Must have privacy shield compliance -Must register with US federal enforcement agency that admins Privacy Shield Admin: DoC Department of Commerce/Enforcer: FTC Admin: DoT Department of Transportation/Enforcer: DoT Binding Corporate Rules / Standard Contractual Clauses - CORRECT ANSWER โโโ US orgs that don't want to comply with Privacy Shield but still need to collect data from EU citizens. -Companies will need to approach every individual EU country they do business with. They need to validate/accept the org's information security policy. APEC - CORRECT ANSWER โโโ Asia-Pacific Economic Cooperation -Not legally binding ISO 27001 - CORRECT ANSWER โโโ Holistic overview of entire security program within an Org. -Top down approach -Industry agnostic -Expensive, well regarded document -Not lawful, but recognized internationally ISO 27017: 2015 - CORRECT ANSWER โโโ Standard guidelines for information security and use of cloud services and cloud service customers. ISO 27018:2019 - CORRECT ANSWER โโโ Code of practice, security techniques for processing PII in cloud services ISO 27050 - CORRECT ANSWER โโโ e-discovery ISO 27043 : 2015 - CORRECT ANSWER โโโ Incident investigation principles and processes ISO 27042 : 2015 - CORRECT ANSWER โโโ Guide for digital evidence analysis