Skip to content
CS-802 (B) · Cloud Computing/Quick Revision Short Notes

Cloud Computing (CS-802 (B)) - Unit 4 Short Notes

How unit 4 is examined

This unit covers cloud security principles, threats, architecture, virtualization security and secure communication; VM-specific security techniques (14 marks), the security reference architecture, the CSA threats and cloud security challenges carry the marks.

Cloud security fundamentals

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>Cloud security is the set of policies, technologies and controls that protect the data, applications and infrastructure of a cloud from threats, on the basis of the CIA triad and the shared responsibility model.</mark>

Key points.

  1. Confidentiality means only authorised users can read data, and it is enforced by encryption and access control.
  2. Integrity means data is not altered without permission, and it is enforced by hashing, digital signatures and checksums.
  3. Availability means services stay reachable when needed, and it is protected by redundancy, backups and DDoS defence.
  4. Shared responsibility means the provider secures the cloud (hardware, hypervisor, facilities) while the customer secures what is in the cloud (data, identities, configuration); the customer's share grows from SaaS to PaaS to IaaS.
  5. Defence in depth stacks several layers (network, host, application, data) so that one failed control does not expose everything.
  6. Identity and access management, least privilege, multi-factor authentication and encryption of data at rest and in transit are the core controls, and network isolation and compliance (audit, logging) complete them.
  7. The Cloud Security Alliance (CSA) is a non-profit body that publishes best practices and the list of top cloud threats. Its top threats are data breaches, data loss, account or service hijacking, insecure interfaces and APIs, denial of service, malicious insiders, abuse of cloud services, insufficient due diligence and shared technology vulnerabilities.
  8. These threats slow cloud adoption because customers lose control and visibility and fear breaches, lock-in and compliance failure.

Answer frame. For principles: open with the definition, list CIA, shared responsibility and defence in depth, then IAM, encryption, isolation, compliance; close with trust. For CSA threats: introduce the CSA in one line, give each threat one sentence, close with the effect on adoption.

Asked: [7 marks] (May 2022) Describe the top threats identified by Cloud Security Alliance (CSA) of cloud computing. Asked: [7 marks] (Jun 2025) Explain the fundamental principles of cloud security.

Vulnerability assessment tool for cloud

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>Vulnerability assessment in the cloud is the systematic scanning of cloud servers, networks, containers and configurations to find, rank and report security weaknesses before attackers exploit them.</mark>

Key points.

  1. Network and vulnerability scanners such as Nessus, Qualys and OpenVAS scan hosts and services for known flaws (CVEs) and missing patches.
  2. Configuration and compliance tools such as AWS Config, Azure Policy and Security Hub check cloud resources against rules, and they belong to cloud security posture management (CSPM).
  3. Penetration testing tools such as Metasploit and Burp Suite actively attack a system, with the provider's permission, to prove that a weakness can be exploited.
  4. Container security tools such as Aqua Security and Twistlock (Prisma Cloud) scan container images and running containers for vulnerabilities.
  5. Infrastructure-as-code scanners such as Checkov and Terraform scanners find insecure templates before deployment.
  6. Tools are either agent-based (installed on each VM) or agentless (using cloud APIs), and continuous monitoring with automated remediation keeps results current.
  7. Their significance is that they find weaknesses early, prioritise them by severity, prove compliance and reduce the chance of a breach.

Answer frame. Open with the definition; group tools by type in a small table (tool, category, use); close with the significance of continuous scanning.

Asked: [7 marks] (May 2024, May 2026) Describe various vulnerability assessment tool for cloud; explain these tools and discuss their significance in identifying security weaknesses in cloud infrastructures.

Privacy and Security in cloud

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>Data access control decides who may read, write or share which enterprise data in the cloud, by authenticating users and authorising them against policy.</mark>

Key points.

  1. Authentication proves identity using passwords, multi-factor authentication, certificates or single sign-on.
  2. Role-Based Access Control (RBAC) gives permissions to roles such as manager or clerk, and users get rights through their role.
  3. Attribute-Based Access Control (ABAC) decides using attributes of user, resource and context, such as department, time and location, so it is finer than RBAC.
  4. Enforcement uses least privilege, encryption of stored data, and audit logs, and it supports compliance with laws on privacy.

Asked: [7 marks] (Dec 2024) Explain Data Access control for enterprise application in cloud.

Cloud computing security architecture

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>A cloud security reference architecture is a layered model that places security controls, identity management and security management around the infrastructure, platform and application layers of a cloud.</mark>

Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u4-01" viewBox="0 0 434.5 338" width="434.5" height="338" role="img" aria-label="Security reference architecture. App = application layer, Plat = platform layer, Infra = infrastructure layer, IAM = identity and access management, Data = data security, Mgmt = security management and monitoring"><style>#dsfig-u4-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u4-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u4-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u4-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u4-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u4-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u4-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u4-01 .t{fill:#16181D;font-weight:500}#dsfig-u4-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u4-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u4-01 .dot{fill:#16181D}#dsfig-u4-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u4-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u4-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u4-01 .ah{fill:#454C5A}#dsfig-u4-01 .ah.hi{fill:#2340B8}#dsfig-u4-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u4-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u4-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u4-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u4-01 .e{stroke:#B1B7C3}html.dark #dsfig-u4-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u4-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u4-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u4-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u4-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u4-01 .t{fill:#E6E8ED}html.dark #dsfig-u4-01 .t.inv{fill:#0F1115}html.dark #dsfig-u4-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u4-01 .dot{fill:#E6E8ED}html.dark #dsfig-u4-01 .ann{fill:#8FA3FF}html.dark #dsfig-u4-01 .lbl{fill:#858D9C}html.dark #dsfig-u4-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u4-01 .ah{fill:#B1B7C3}html.dark #dsfig-u4-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u4-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u4-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u4-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah10" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh10" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M212,59 L212,100"/><path class="e" d="M212,152 L212,182.5"/><path class="e" d="M59,126 L184,126" marker-end="url(#ah10)"/><path class="e" d="M358,126 L240,126" marker-end="url(#ah10)"/><path class="e" d="M212,272 L212,243.5" marker-end="url(#ah10)"/><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">App</text><rect class="n" x="187" y="111" width="50" height="30" rx="15"/><text class="t" x="212" y="126" dy=".35em" text-anchor="middle">Plat</text><rect class="n" x="183.5" y="197" width="57" height="30" rx="15"/><text class="t" x="212" y="212" dy=".35em" text-anchor="middle">Infra</text><circle class="n" cx="40" cy="126" r="18"/><text class="t" x="40" y="126" dy=".35em" text-anchor="middle">IAM</text><rect class="n" x="359" y="111" width="50" height="30" rx="15"/><text class="t" x="384" y="126" dy=".35em" text-anchor="middle">Data</text><rect class="n" x="187" y="283" width="50" height="30" rx="15"/><text class="t" x="212" y="298" dy=".35em" text-anchor="middle">Mgmt</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Security reference architecture. App = application layer, Plat = platform layer, Infra = infrastructure layer, IAM = identity and access management, Data = data security, Mgmt = security management and monitoring</figcaption></figure>

Key points.

  1. The infrastructure layer secures physical servers, network, storage and the hypervisor through firewalls, isolation and physical controls.
  2. The platform layer secures middleware, runtime and APIs through patching, secure configuration and API gateways.
  3. The application layer secures software through secure coding, input validation and web application firewalls.
  4. Identity and access management provides authentication, authorization and single sign-on across all layers.
  5. Authentication verifies who the user is; authorization decides what that user may do, using RBAC or ABAC.
  6. Data security uses encryption at rest and in transit, key management and data loss prevention.
  7. Network security uses firewalls, VPN, intrusion detection and segmentation between tenants.
  8. Security management covers logging, monitoring, incident response and compliance, and it connects to every layer through interfaces.

Answer frame. Open with the definition; draw the layered diagram with IAM, data security and management as side columns; develop the layers bottom to top, then IAM, encryption and management; close that layered controls give defence in depth. For the authentication, authorization and encryption question, spend points 4-6 as the main body.

Asked: [7 marks] (May 2023, May 2026) Explain Security Reference Architecture of Cloud with a neat Diagram; describe cloud computing security architecture and explain the role of authentication, authorization and encryption mechanisms in cloud environments.

General Issues

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>General security issues are the common risks of cloud computing, such as data leakage, unauthorised access and insider attacks, which arise from sharing resources and giving up direct control of them.</mark>

Key points.

  1. Data leakage is exposure of sensitive data to unauthorised parties, caused by misconfigured storage, weak encryption or another tenant's flaw.
  2. Unauthorised access happens through stolen credentials, weak IAM, open ports or insecure APIs.
  3. An insider attack is misuse of access by an employee of the customer or provider, and it is hard to detect because the insider is trusted.
  4. Multi-tenancy, misconfiguration and weak IAM are the main causes, and the impact is loss of confidentiality, integrity and compliance.
  5. Mitigation uses encryption, MFA, least privilege, monitoring, audits and staff screening.
  6. When a risk has no mitigation strategy, the organisation handles it by accepting it (knowingly living with a small risk), avoiding it (not using that service or data), or transferring it (insurance or contract terms in the SLA).
  7. It also sets up continuous monitoring, a contingency and disaster recovery plan, a clear security policy and an incident response team, so damage is limited when the risk occurs.

Answer frame. For issues: define the three, give causes, impact, then mitigation. For no-mitigation risks: open with accept, avoid, transfer, then monitoring, contingency plan, policy and incident response.

Asked: [7 marks] (Dec 2024) How does an organization handle the identified security challenges which has no mitigation strategies? Asked: [7 marks] (May 2026) Analyze general security issues associated with cloud computing systems including data leakage, unauthorized access and insider attacks.

Trusted Cloud computing

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>Trusted cloud computing is a cloud whose platform and provider can be verified as secure, so customers can rely on the integrity of their data and workloads.</mark>

Key points.

  1. The trust model is built on a hardware root of trust, the Trusted Platform Module (TPM), which stores keys and measurements.
  2. Secure boot checks that each boot component is signed before it runs, so tampered firmware or hypervisor is blocked.
  3. Remote attestation lets the customer check the measured state of a host before placing a VM on it.
  4. The benefit is data assurance: workloads run only on verified hosts, and integrity and confidentiality can be proved to the customer.

Asked: [7 marks] (Dec 2024) What is trusted cloud computing? Explain.

Security challenges: Virtualization security management-virtual threats

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>Cloud security challenges are the obstacles to keeping data and services safe in a shared, virtualized, provider-controlled environment.</mark>

Key points.

  1. Data breach and data loss occur through attacks, deletion or provider failure, so customers need encryption and backups.
  2. Account hijacking means an attacker steals credentials and controls the customer's services.
  3. Insecure interfaces and APIs expose the cloud to attack if they lack authentication and validation.
  4. Insider threats come from staff with privileged access.
  5. Multi-tenancy means many customers share hardware, so isolation failure can leak data between them.
  6. Compliance and legal issues arise because data may be stored in other countries under different laws.
  7. Availability and SLA concerns arise from outages and denial-of-service attacks, and lack of transparency and trust makes them harder to audit.
  8. Virtualization adds virtual threats such as VM escape and hypervisor attacks (see VM-specific techniques).

Answer frame. Open with the definition; list challenges as numbered heads with one sentence each; close with impact on confidentiality, integrity and availability.

Asked: [7 marks] (May 2023, Dec 2024) What are the different Security Challenges in Cloud computing? Discuss in brief.

VM Security Recommendations

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>VM security recommendations are the best practices that harden virtual machines and their hypervisor against attack.</mark>

Key points.

  1. Harden and patch the guest OS, use minimal images and disable unused services.
  2. Secure the hypervisor by patching it and restricting management access.
  3. Isolate VMs and use network segmentation with virtual firewalls.
  4. Control access with least privilege and MFA for administrators.
  5. Encrypt VM disks and snapshots, run anti-malware, monitor logs and take regular backups.

Asked: [7 marks] (Jun 2025) What are the key security recommendations for securing virtual machines (VMs)?

VM-Specific Security techniques

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. <mark>Virtual threats are security risks specific to virtualized environments, such as VM escape and hypervisor compromise, and VM-specific security techniques are the controls that isolate and protect virtual machines against them.</mark>

Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u4-02" viewBox="0 0 424 338" width="424" height="338" role="img" aria-label="VMs on one hypervisor (Hyp) over shared hardware (HW). A compromised hypervisor or an escape from one VM exposes all."><style>#dsfig-u4-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u4-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u4-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u4-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u4-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u4-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u4-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u4-02 .t{fill:#16181D;font-weight:500}#dsfig-u4-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u4-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u4-02 .dot{fill:#16181D}#dsfig-u4-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u4-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u4-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u4-02 .ah{fill:#454C5A}#dsfig-u4-02 .ah.hi{fill:#2340B8}#dsfig-u4-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u4-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u4-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u4-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u4-02 .e{stroke:#B1B7C3}html.dark #dsfig-u4-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u4-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u4-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u4-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u4-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u4-02 .t{fill:#E6E8ED}html.dark #dsfig-u4-02 .t.inv{fill:#0F1115}html.dark #dsfig-u4-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u4-02 .dot{fill:#E6E8ED}html.dark #dsfig-u4-02 .ann{fill:#8FA3FF}html.dark #dsfig-u4-02 .lbl{fill:#858D9C}html.dark #dsfig-u4-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u4-02 .ah{fill:#B1B7C3}html.dark #dsfig-u4-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u4-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u4-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u4-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah11" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh11" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M55.2,51.4 L195.2,156.4" marker-end="url(#ah11)"/><path class="e" d="M212,59 L212,148" marker-end="url(#ah11)"/><path class="e" d="M368.8,51.4 L228.8,156.4" marker-end="url(#ah11)"/><path class="e" d="M212,188 L212,277" marker-end="url(#ah11)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">VM1</text><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">VM2</text><circle class="n" cx="384" cy="40" r="18"/><text class="t" x="384" y="40" dy=".35em" text-anchor="middle">VM3</text><circle class="n" cx="212" cy="169" r="18"/><text class="t" x="212" y="169" dy=".35em" text-anchor="middle">Hyp</text><circle class="n" cx="212" cy="298" r="18"/><text class="t" x="212" y="298" dy=".35em" text-anchor="middle">HW</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">VMs on one hypervisor (Hyp) over shared hardware (HW). A compromised hypervisor or an escape from one VM exposes all.</figcaption></figure>

Key points.

  1. VM escape is when an attacker breaks out of a VM's boundary to reach the host hypervisor or other VMs.
  2. Hypervisor attacks target the hypervisor, and since it controls all VMs, its compromise affects every VM on the host.
  3. Side-channel attacks infer secrets, such as keys, from shared cache or CPU timing between co-resident VMs.
  4. Privilege escalation raises rights inside a VM, or from the VM to the host, and VM sprawl, snapshot theft and VM migration interception add further risks.
  5. Hypervisor hardening means minimal code, regular patching and restricted management interfaces.
  6. Isolation techniques use memory protection and CPU isolation (for example hardware virtualization extensions) so that one VM cannot read another's memory or cycles.
  7. Secure boot and remote attestation confirm that the hypervisor and VM images are untampered, and encrypted VM state (disks, snapshots, migration traffic) protects data.
  8. Intrusion detection at the hypervisor level, virtual firewalls and network segmentation monitor traffic between VMs.

Answer frame. Open by defining virtual threats; draw the diagram; develop threats 1-4, then techniques 5-8; close that layered isolation limits the effect of one compromised VM. For the short-note form, use the definition and points 5-8.

Asked: [14 marks] (May 2024, May 2026) What is virtual threats? Explain VM specific security techniques. Also: short note on VM Security Techniques and Secure Execution Environments.

Secure Execution Environments and Communications in cloud

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>Secure communication in the cloud means data moving between users and the cloud, or between cloud components, keeps confidentiality, integrity and authentication.</mark>

Key points.

  1. SSL/TLS encrypts web traffic and authenticates the server with a certificate, after a handshake that agrees a session key.
  2. A VPN builds an encrypted tunnel between the customer network and the cloud over the internet, and IPSec secures the traffic at the IP layer.
  3. Encryption with proper key management (key rotation, hardware security modules) protects data in transit.
  4. Identity management and access control (authentication, then authorization) ensure only verified parties use the channel.
  5. A secure execution environment isolates code using VMs, containers or hardware enclaves so it runs protected.

Asked: [7 marks] (May 2023) What do you understand by Secure Communication in Cloud? How it is achieved?

Last-minute revision

  • CIA triad: confidentiality, integrity, availability; shared responsibility: provider secures the cloud, customer secures what is in it.
  • CSA top threats: data breach, data loss, account hijacking, insecure APIs, DoS, malicious insiders, abuse, shared technology vulnerabilities.
  • Vulnerability tools: Nessus, Qualys, OpenVAS (scanners); AWS Config, Azure Policy (compliance); Metasploit, Burp Suite (pentest); Aqua, Twistlock (containers); Checkov (IaC).
  • RBAC uses roles; ABAC uses attributes.
  • Reference architecture: infrastructure, platform, application layers plus IAM, data security and security management.
  • Risk with no mitigation: accept, avoid, transfer, plus monitoring, contingency, policy, incident response.
  • Trusted cloud: TPM, secure boot, remote attestation.
  • VM escape breaks out of the VM; a hypervisor compromise affects all VMs.
  • VM techniques: hypervisor hardening, memory and CPU isolation, secure boot, attestation, hypervisor IDS, encrypted VM state.
  • Secure communication: TLS, VPN, IPSec, encryption with key management.

Memory hooks

  • CIA and shared duty: "provider guards the building, you guard your room."
  • Risk options: A-A-T (accept, avoid, transfer).
  • VM techniques: "Harden, Isolate, Boot-check, Encrypt, Watch".
  • Secure channel: "TLS for web, VPN for site, IPSec for IP."

Coverage checklist

  • Cloud security fundamentals: CSA top threats; fundamental principles of cloud security.
  • Vulnerability assessment tool for cloud: vulnerability assessment tools and significance.
  • Privacy and Security in cloud: data access control for enterprise applications.
  • Cloud computing security architecture: security reference architecture with diagram; authentication, authorization, encryption.
  • General Issues: no-mitigation risks; data leakage, unauthorised access, insider attacks.
  • Trusted Cloud computing: what is trusted cloud computing.
  • Security challenges: Virtualization security management-virtual threats: security challenges in cloud.
  • VM Security Recommendations: key recommendations for securing VMs.
  • VM-Specific Security techniques: virtual threats and VM-specific techniques; short note on VM security techniques.
  • Secure Execution Environments and Communications in cloud: secure communication in cloud.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in