Skip to Content
Practical Cloud Security, 2nd Edition
book

Practical Cloud Security, 2nd Edition

by Chris Dotson
October 2023
Intermediate to advanced
230 pages
6h 47m
English
O'Reilly Media, Inc.
Book available
Content preview from Practical Cloud Security, 2nd Edition

Appendix. Exercise Solutions

Here are the answers for the exercises at the end of each chapter.

Chapter 1

  1. A, C, and D. Requiring multi-factor authentication is also a good idea, but it’s an example of the principle of defense in depth, not least privilege.

  2. A and D. Strict firewall controls may help, but they don’t demonstrate defense in depth unless paired with another control. Trust boundaries are also important, and may be used to define controls, but are not a defense in depth control.

  3. A, B, C, and D. Threat actors may want to do all of these things, although historically making money is by far the largest motivator. In addition, some threat actors may be motivated simply by the challenge of breaking in or enhancing their reputations in hacking circles.

  4. A. Depending on the service delivery model, network security and operating security may be the cloud provider’s responsibility, or may not be. Data access security—choosing who gets access to the data—is almost always the consumer’s responsibility.

  5. A and B. Most risk assessment systems use some form of likelihood and impact assessment to determine the overall risk level. Transferring a risk doesn’t determine the severity of the risk, but may be a way to deal with the risk. Your risk severity is also not directly affected by whether the attacker’s actions are legal or not, although taking illegal actions may raise the attacker’s risk of going to jail.

Chapter 2

  1. A. While you may need more than 3 data classification ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Cloud Security

Practical Cloud Security

Chris Dotson

Publisher Resources

ISBN: 9781098148164Errata Page