Unit 6: Cloud Security - Subjective Questions

INT363 — Cloud Microservices • Practice Questions with Detailed Answers

20 questions

1

Define cloud security and explain the major security issues encountered in cloud computing.

2

Explain the shared responsibility architecture in cloud security. How does responsibility change across IaaS, PaaS, and SaaS?

3

Describe the major security-by-design principles that should be applied while developing cloud-native and microservices-based systems.

4

Explain Identity and Access Management in the cloud. Discuss authentication, authorization, federation, and the principle of least privilege.

5

Illustrate and explain the layers of a cloud security architecture.

6

Describe the main cloud network security concepts and controls used to protect cloud workloads.

7

Explain host security concepts for virtual machines, containers, and cloud workloads.

8

Discuss cloud data security throughout the data lifecycle, including encryption and key management.

9

What is cloud security operations? Explain the major activities involved in detecting and responding to cloud threats.

10

Compare important security tools offered by AWS, Microsoft Azure, and Google Cloud.

11

Explain the significance of security compliance and regulations in cloud computing. Mention important standards and legal requirements.

12

Describe the security and management challenges caused by interoperability and vendor lock-in in multi-cloud and hybrid-cloud environments.

13

Explain monitoring and performance management in cloud systems. Which metrics and observability signals should be collected?

14

Describe a cloud incident response lifecycle and explain how cloud characteristics affect digital forensics.

15

Discuss major future trends and innovations that are expected to influence cloud security.

16

What is edge computing? Explain its security benefits and security challenges when integrated with cloud systems.

17

Explain how artificial intelligence can improve cloud security and discuss the new risks created by AI-based cloud systems.

18

Distinguish between perimeter-based security and zero-trust security in cloud environments.

19

Explain how DevSecOps can secure the lifecycle of cloud microservices and their software supply chain.

20

Design a layered security approach for a cloud-hosted microservices application that processes sensitive customer data.