BTCE | 5th Sem
SPC SubjectUnit 3

SPC Unit 3: Questions & Answers

Unit 3: Cloud Security Design Patterns -> Generated and Prepared By Thiruselvan (ThiruXD)

Introduction to Design Patterns

Q1. What is a design pattern?

  1. A random diagram
  2. A reusable solution to a recurring design problem
  3. A software license
  4. A cloud pricing model

Answer: B) A reusable solution to a recurring design problem -> Explanation: A design pattern is a proven and reusable solution to a recurring design problem. In cloud security, design patterns help teams apply security consistently across different workloads, applications, networks, and data flows.


Q2. Which of the following is NOT a reason for using security design patterns?

  1. Consistency
  2. Scalability
  3. Increasing cloud cost
  4. Auditability

Answer: C) Increasing cloud cost -> Explanation: Security design patterns provide consistency, scalability, auditability, risk reduction, and communication. They do not increase cloud cost; in fact, they can optimize costs.


Q3. Which pattern element states the recurring issue that must be solved?

  1. Context
  2. Problem
  3. Forces
  4. Solution

Answer: B) Problem -> Explanation: The Problem element states the recurring issue that must be solved. Example: Users need secure access to cloud APIs from different locations.


Q4. Which pattern element lists competing requirements and constraints?

  1. Problem
  2. Context
  3. Forces
  4. Controls

Answer: C) Forces -> Explanation: Forces list competing requirements and constraints such as security, performance, cost, latency, compliance, and user convenience.


Q5. Which pattern element defines how to test the pattern?

  1. Controls
  2. Benefits
  3. Risks
  4. Verification

Answer: D) Verification -> Explanation: Verification defines how to test the pattern, such as access tests, penetration tests, log reviews, and policy simulation.


Q6. Which category of design patterns controls who or what can access resources?

  1. Network security patterns
  2. Identity and access patterns
  3. Data protection patterns
  4. Interface security patterns

Answer: B) Identity and access patterns -> Explanation: Identity and access patterns control who or what can access resources. Examples include RBAC, ABAC, MFA, SSO, and identity federation.


Q7. Which category of design patterns protects APIs, portals, CLIs, and SDKs?

  1. Identity and access patterns
  2. Network security patterns
  3. Interface security patterns
  4. Data protection patterns

Answer: C) Interface security patterns -> Explanation: Interface security patterns protect APIs, portals, CLIs, SDKs, and service endpoints. Examples include API gateway, WAF, OAuth/OIDC, and rate limiting.


Q8. Which category of design patterns governs connections to third-party cloud and SaaS providers?

  1. Hybrid integration patterns
  2. External integration patterns
  3. Network security patterns
  4. Data protection patterns

Answer: B) External integration patterns -> Explanation: External integration patterns govern connections to third-party cloud and SaaS providers. Examples include webhook verification, partner API scopes, and cross-tenant access review.


Cloud Bursting

Q9. What is cloud bursting?

  1. Deleting cloud resources
  2. Expanding capacity during demand spikes
  3. Disabling network access
  4. Replacing all security controls

Answer: B) Expanding capacity during demand spikes -> Explanation: Cloud bursting is a hybrid cloud pattern where an application runs mainly in a private environment but expands into a public cloud during demand spikes.


Q10. Which of the following is a security concern for cloud bursting?

  1. Burst resources must receive the same security policies
  2. Temporary resources should be removed securely
  3. Data residency and privacy rules must be respected
  4. All of the above

Answer: D) All of the above -> Explanation: All are security concerns: burst resources must receive the same security policies, temporary resources should be removed securely, and data residency and privacy rules must be respected.


Q11. Which component provides secure connectivity in cloud bursting?

  1. Load balancer
  2. VPN, private link, or encrypted tunnel
  3. API gateway
  4. Firewall

Answer: B) VPN, private link, or encrypted tunnel -> Explanation: Secure connectivity in cloud bursting uses VPN, private link, dedicated connection, or encrypted tunnel to protect traffic between on-premise and cloud.


Q12. What is the first step in the cloud bursting workflow?

  1. Deploy cloud resources
  2. Monitor application load
  3. Route traffic
  4. Decommission resources

Answer: B) Monitor application load -> Explanation: The first step is to monitor application load, response time, and resource utilization in the private environment.


Q13. What should be done after peak load ends in cloud bursting?

  1. Keep resources running
  2. Decommission resources and revoke access
  3. Disable logs
  4. Remove security policies

Answer: B) Decommission resources and revoke access -> Explanation: After peak load ends, drain sessions, remove public cloud resources, archive logs, and revoke temporary access to reduce residual risk.


Q14. Which security control is used for data in cloud bursting?

  1. Classify data before bursting and encrypt replication
  2. Share all data with public cloud
  3. Disable encryption
  4. Use public storage

Answer: A) Classify data before bursting and encrypt replication -> Explanation: Classify data before bursting and encrypt replication traffic to prevent sensitive data from moving to unauthorized regions.


Q15. Which of the following is an advantage of cloud bursting?

  1. Improves elasticity without permanent hardware investment
  2. Increases permanent hardware cost
  3. Eliminates all security risks
  4. Removes need for monitoring

Answer: A) Improves elasticity without permanent hardware investment -> Explanation: Cloud bursting improves elasticity without permanent hardware investment. It supports seasonal and event-based traffic spikes.


Geo-Tagging

Q16. What is geo-tagging in cloud security?

  1. Changing file names
  2. Attaching location-based metadata to data and resources
  3. Increasing screen resolution
  4. Removing encryption

Answer: B) Attaching location-based metadata to data and resources -> Explanation: Geo-tagging is the process of adding geographic or location-based metadata to cloud data, users, devices, workloads, logs, or resources.


Q17. Geo-tagging helps with:

  1. Data residency and location-aware policy
  2. Screen resolution
  3. File compression
  4. Password management

Answer: A) Data residency and location-aware policy -> Explanation: Geo-tagging helps enforce policies related to data residency, regional compliance, access location, backup placement, disaster recovery, and privacy.


Q18. Which geo-tag would be used for a data object?

  1. country=India, region=ap-south
  2. name=Alice
  3. age=25
  4. role=admin

Answer: A) country=India, region=ap-south -> Explanation: Geo-tags for a data object include country and region, such as country=India, region=ap-south. These prevent unauthorized cross-border transfer.


Q19. Which risk is associated with geo-tagging?

  1. Incorrect tags
  2. Location spoofing
  3. Tag bypass
  4. All of the above

Answer: D) All of the above -> Explanation: Risks include incorrect tags, location spoofing, privacy risk, tag bypass, compliance drift, and replication mismatch.


Q20. What is the control for incorrect tags?

  1. Use automated tagging and mandatory tag policies
  2. Manual tagging
  3. Ignore tags
  4. Delete all tags

Answer: A) Use automated tagging and mandatory tag policies -> Explanation: The control for incorrect tags is to use automated tagging and mandatory tag policies to prevent manual tagging errors.


Q21. Which use case of geo-tagging ensures data remains within approved legal jurisdictions?

  1. Data residency
  2. Access control
  3. Disaster recovery
  4. Cost and performance

Answer: A) Data residency -> Explanation: Data residency ensures data remains within approved legal jurisdictions. Example: Customer data stored only in Indian cloud regions.


Q22. Which geo-tagging use case helps investigators identify where data moved and who accessed it?

  1. Data residency
  2. Incident response
  3. Cost and performance
  4. Legal compliance

Answer: B) Incident response -> Explanation: Incident response helps investigators identify where data moved and who accessed it. Logs show access from abnormal location.


Secure Cloud Interfaces

Q23. Which component commonly protects APIs through authentication, rate limiting, and request validation?

  1. API gateway
  2. Spreadsheet
  3. Printer
  4. Unmanaged file share

Answer: A) API gateway -> Explanation: An API gateway is a controlled entry point that enforces authentication, authorization, rate limiting, TLS termination, request validation, and logging.


Q24. Which of the following is a type of cloud interface?

  1. Management console
  2. REST API
  3. CLI
  4. All of the above

Answer: D) All of the above -> Explanation: Cloud interfaces include management consoles, REST APIs, CLIs, SDKs, service endpoints, automation pipelines, and webhooks.


Q25. Which security requirement applies to a management console?

  1. MFA, SSO, conditional access, audit logging
  2. No authentication
  3. Public access
  4. Plain HTTP

Answer: A) MFA, SSO, conditional access, audit logging -> Explanation: Management consoles require MFA, SSO, conditional access, and audit logging to protect administrative access.


Q26. Which protocol is used for secure API authentication?

  1. OAuth/OIDC
  2. FTP
  3. Telnet
  4. HTTP

Answer: A) OAuth/OIDC -> Explanation: OAuth/OIDC is used for secure API authentication. It provides token-based access control.


Q27. What is the role of rate limiting in API security?

  1. Increases brute force risk
  2. Reduces brute force and denial-of-service risk
  3. Disables authentication
  4. Removes logging

Answer: B) Reduces brute force and denial-of-service risk -> Explanation: Rate limiting reduces brute force and denial-of-service risk by limiting the number of requests per client.


Q28. Which threat involves a user changing an object ID to access another user’s data?

  1. Broken object authorization
  2. Excessive permissions
  3. Credential exposure
  4. Injection attacks

Answer: A) Broken object authorization -> Explanation: Broken object authorization occurs when a user changes an object ID to access another user’s data. Mitigation: Check authorization for every object access.


Q29. Which threat involves secrets stored in source code or logs?

  1. Broken object authorization
  2. Credential exposure
  3. API abuse
  4. Weak TLS

Answer: B) Credential exposure -> Explanation: Credential exposure occurs when secrets are stored in source code or logs. Mitigation: Use secret vaults and scanning.


Q30. Which security control helps reduce API abuse?

  1. Rate limiting
  2. Unrestricted tokens
  3. Public storage
  4. Disabled authentication

Answer: A) Rate limiting -> Explanation: Rate limiting helps reduce API abuse by limiting the number of requests a client can make in a given time period.


Cloud Resource Access Control

Q31. What does RBAC stand for?

  1. Resource Backup and Copy
  2. Role-Based Access Control
  3. Regional Business Accounting Code
  4. Remote Binary Access Channel

Answer: B) Role-Based Access Control -> Explanation: RBAC stands for Role-Based Access Control. Access is based on assigned roles, such as DatabaseAdmin can manage database instances.


Q32. What does ABAC stand for?

  1. Attribute-Based Access Control
  2. Automated Backup and Copy
  3. Advanced Binary Access Code
  4. Application-Based Access Control

Answer: A) Attribute-Based Access Control -> Explanation: ABAC stands for Attribute-Based Access Control. Access is based on attributes of user, resource, action, and context.


Q33. Which access control model uses resource tags in policy conditions?

  1. RBAC
  2. ABAC
  3. Tag-based access
  4. Just-in-time access

Answer: C) Tag-based access -> Explanation: Tag-based access uses resource tags in policy conditions. Example: Developers can start resources tagged environment=dev.


Q34. What is the principle of least privilege?

  1. Give all users administrator access
  2. Give only the minimum required permissions
  3. Disable all logs
  4. Use the same password everywhere

Answer: B) Give only the minimum required permissions -> Explanation: Least privilege is a security principle that gives users and services only the minimum permissions required to perform their work.


Q35. Which component evaluates whether a request should be allowed?

  1. Policy Decision Point
  2. Policy Enforcement Point
  3. Policy Administration Point
  4. Policy Information Point

Answer: A) Policy Decision Point -> Explanation: The Policy Decision Point evaluates whether a request should be allowed. Example: IAM policy engine.


Q36. Which component enforces the allow or deny decision?

  1. Policy Decision Point
  2. Policy Enforcement Point
  3. Policy Administration Point
  4. Policy Information Point

Answer: B) Policy Enforcement Point -> Explanation: The Policy Enforcement Point enforces the allow or deny decision. Example: API gateway, proxy, storage service, firewall.


Q37. What is just-in-time access?

  1. Permanent admin roles
  2. Privileges granted temporarily when needed
  3. No access control
  4. Shared credentials

Answer: B) Privileges granted temporarily when needed -> Explanation: Just-in-time access grants privileges temporarily when needed. Example: Admin role activated for one hour after approval.


Q38. Which is a dangerous access control mistake?

  1. Using named admin roles
  2. Using root or owner account for daily work
  3. Performing access reviews
  4. Using just-in-time access

Answer: B) Using root or owner account for daily work -> Explanation: Using root or owner account for daily work is dangerous because a compromise gives full control. Better practice: Use named admin roles with MFA and auditing.


Q39. Which is a control for unrotated access keys?

  1. Use short-lived credentials and rotation
  2. Keep keys forever
  3. Share keys publicly
  4. Store keys in code

Answer: A) Use short-lived credentials and rotation -> Explanation: Unrotated access keys are dangerous because stolen keys remain useful for long periods. Control: Use short-lived credentials and rotation.


Secure On-Premise Internet Access

Q40. Which tool is commonly used to monitor and govern cloud application usage?

  1. CASB
  2. Compiler
  3. Image editor
  4. Text editor

Answer: A) CASB -> Explanation: CASB (Cloud Access Security Broker) is a security control point that monitors and governs access to cloud applications. It detects shadow IT and enforces SaaS DLP policies.


Q41. Which component inspects web traffic before it reaches the internet?

  1. Proxy / Secure Web Gateway
  2. Printer
  3. Spreadsheet
  4. Compiler

Answer: A) Proxy / Secure Web Gateway -> Explanation: A Proxy / Secure Web Gateway inspects web traffic before it reaches the internet. It performs URL filtering, malware detection, and TLS inspection.


Q42. Which component blocks malicious domains before connection occurs?

  1. DNS Security
  2. Firewall
  3. DLP
  4. SIEM

Answer: A) DNS Security -> Explanation: DNS Security blocks malicious domains before connection occurs. It prevents command-and-control domain access.


Q43. Which component prevents leakage of sensitive data?

  1. DLP
  2. Firewall
  3. Proxy
  4. IDS

Answer: A) DLP -> Explanation: DLP (Data Loss Prevention) prevents leakage of sensitive data. It blocks confidential files uploaded to unapproved services.


Q44. What is the difference between full tunnel and split tunnel?

  1. Full tunnel routes all traffic through enterprise controls; split tunnel routes selected traffic
  2. Full tunnel is faster; split tunnel is slower
  3. Full tunnel has no security; split tunnel has security
  4. Full tunnel is for remote users only

Answer: A) Full tunnel routes all traffic through enterprise controls; split tunnel routes selected traffic -> Explanation: Full tunnel routes all user traffic through enterprise security controls (maximum visibility). Split tunnel routes only selected traffic through enterprise controls (better performance).


Q45. Which approach grants access to specific applications rather than broad network access?

  1. Full tunnel
  2. Split tunnel
  3. Zero-trust access
  4. VPN

Answer: C) Zero-trust access -> Explanation: Zero-trust access grants access to specific applications rather than broad network access. It limits lateral movement.


Secure External Cloud Integration

Q46. A webhook endpoint should be protected using:

  1. Signature verification and replay protection
  2. Anonymous unrestricted access
  3. No logging
  4. Plain HTTP only

Answer: A) Signature verification and replay protection -> Explanation: Webhook endpoints should be protected using signature verification, timestamp checks, and replay protection to prevent attacks.


Q47. Which item is most suitable for protecting secrets used in external integrations?

  1. Plain text file
  2. Source code comments
  3. Managed secrets vault
  4. Public chat message

Answer: C) Managed secrets vault -> Explanation: A managed secrets vault is most suitable for protecting secrets. It stores and rotates credentials securely.


Q48. Which integration type connects an enterprise application to an external SaaS service?

  1. SaaS integration
  2. Partner API
  3. Cross-cloud integration
  4. Webhook integration

Answer: A) SaaS integration -> Explanation: SaaS integration connects an enterprise application to an external SaaS service. Examples: CRM, HRMS, email, learning management system.


Q49. What is the risk of excessive third-party access?

  1. Provider receives more data or permissions than required
  2. Provider has no access
  3. Data is encrypted
  4. Logs are disabled

Answer: A) Provider receives more data or permissions than required -> Explanation: Excessive third-party access means the provider receives more data or permissions than required. Control: Use minimal scopes and contractual data limits.


Q50. Which is a control for provider compromise?

  1. Monitor integration behaviour and revoke tokens quickly
  2. Ignore provider activity
  3. Share more data
  4. Disable logging

Answer: A) Monitor integration behaviour and revoke tokens quickly -> Explanation: Provider compromise occurs when an external system is attacked and used to access enterprise data. Control: Monitor integration behaviour and revoke tokens quickly.


SECTION B: THEORY QUESTIONS (20)


Q1. Define cloud security design pattern. Explain why design patterns are important in cloud architecture.

Answer:

A cloud security design pattern is a reusable architectural solution for common security problems that occur in cloud and hybrid cloud environments. It helps architects and engineers design systems that are secure, scalable, auditable, and aligned with business requirements.

Why Design Patterns Are Important:

ReasonExplanationExample
ConsistencyApply the same security logic across multiple applicationsAll APIs use the same gateway, logging, and authorization checks
ScalabilitySecurity controls scale with dynamic cloud resourcesNew instances receive baseline firewall and IAM policies automatically
AuditabilityPatterns define expected controls, making audits easierA storage access pattern includes encryption, logging, and role review
Risk ReductionKnown weak points are addressed before deploymentExternal integrations use token rotation and restricted scopes
CommunicationTeams use a common vocabulary“Use secure interface pattern” instead of listing every API control

Best Practice: Design patterns should be supported by policy as code, infrastructure as code, automated testing, and continuous monitoring.


Q2. Explain the structure of a cloud security design pattern.

Answer:

A good cloud security design pattern explains the problem, when the pattern is suitable, what controls are required, what risks remain, and how implementation can be verified.

Pattern ElementPurposeSecurity Example
ProblemStates the recurring issueUsers need secure access to cloud APIs from different locations
ContextExplains where the problem appearsHybrid cloud, mobile users, SaaS integration
ForcesLists competing requirementsSecurity, performance, cost, latency, compliance
SolutionDescribes architecture and control flowAPI gateway, identity provider, MFA, WAF, centralized logs
ControlsLists required security mechanismsTLS, IAM policy, logging, rate limiting, secrets management
BenefitsExplains positive outcomesReduced attack surface, better visibility, easier governance
RisksMentions limitations and misuse casesMisconfigured policies, stale tokens, poor monitoring
VerificationDefines how to test the patternAccess tests, penetration test, log review, policy simulation

Q3. Explain the cloud bursting pattern with a suitable example.

Answer:

Cloud bursting is a hybrid cloud design pattern in which an application normally runs in a private cloud or on-premise data centre, but temporarily expands into a public cloud when demand increases.

Example: A university admission portal may run on its private servers during normal days. During admission result days, traffic may increase suddenly. Instead of buying permanent hardware for a short peak period, the system can burst into a public cloud and run additional application instances there.

Architecture Components:

  1. Private environment (primary data centre)
  2. Public cloud environment (temporary capacity)
  3. Secure connectivity (VPN, private link)
  4. Traffic management (load balancer, DNS)
  5. Identity federation
  6. Data synchronization
  7. Centralized monitoring
  8. Automation templates

Workflow:

  1. Monitor load
  2. Trigger automation
  3. Apply security baseline
  4. Route traffic
  5. Synchronize data
  6. Monitor both environments
  7. Decommission resources

Q4. What is geo-tagging? How does it support data residency and compliance?

Answer:

Geo-tagging is the process of adding geographic or location-based metadata to cloud data, users, devices, workloads, logs, or resources.

Support for Data Residency:

  • Tags like country=India, region=ap-south ensure data remains within approved legal jurisdictions
  • Policy engines block movement of data to unapproved cloud regions
  • Example: Customer data stored only in Indian cloud regions

Support for Compliance:

  • Supports audits by proving resource and data location
  • Demonstrates that regulated records never left approved jurisdictions
  • Tracks backup and replica locations for disaster recovery
  • Logs every allowed or denied movement of sensitive data

Use Cases:

  1. Data residency
  2. Access control (block admin login from unexpected countries)
  3. Disaster recovery
  4. Incident response
  5. Cost and performance
  6. Legal compliance

Risks and Controls:

RiskControl
Incorrect tagsUse automated tagging and mandatory tag policies
Location spoofingCombine geo-location with device posture and behaviour analytics
Privacy riskMinimize location detail and protect logs
Tag bypassBlock deployment when mandatory tags are missing

Q5. List and explain any five controls used to secure cloud interfaces.

Answer:

Cloud interfaces are entry points used to access cloud resources (APIs, consoles, CLIs, SDKs, endpoints).

Five Security Controls:

  1. Strong Authentication:
    • Use MFA, SSO, and conditional access
    • Verify identity before request processing
    • Example: JWT validation using identity provider public keys
  2. Authorization:
    • Separate authentication from authorization
    • Check whether the caller may access the operation
    • Example: Only finance role can call billing API
  3. API Gateway:
    • Controlled entry point between clients and backend services
    • Enforces authentication, authorization, rate limiting, TLS termination
    • Example: Log request ID, caller, resource, and decision
  4. Rate Limiting:
    • Reduces brute force and denial-of-service risk
    • Limits requests per client
    • Example: Maximum 100 requests per minute per client
  5. Input Validation:
    • Validates all input, request size, schema, content type
    • Blocks malformed or unexpected requests
    • Example: Reject request body that does not match schema

Additional Controls: TLS/mTLS, logging, WAF, secrets management, credential rotation.


Q6. Differentiate between RBAC, ABAC, and tag-based access control.

Answer:

ModelDescriptionCloud Example
RBACAccess is based on assigned rolesDatabaseAdmin can manage database instances
ABACAccess is based on attributes of user, resource, action, and contextAllow access only if department=user.department and device is compliant
Tag-based accessResource tags are used in policy conditionsDevelopers can start resources tagged environment=dev

RBAC (Role-Based Access Control):

  • Users are assigned roles
  • Permissions are attached to roles
  • Simple to manage
  • Example: Admin, Developer, Auditor roles

ABAC (Attribute-Based Access Control):

  • Access decisions based on attributes
  • User attributes (department, role)
  • Resource attributes (sensitivity, owner)
  • Context attributes (time, location, device)
  • More flexible and fine-grained

Tag-Based Access Control:

  • Uses resource tags in policy conditions
  • Tags like environment=dev, region=India
  • Enables dynamic policy enforcement
  • Example: Developers can start only environment=dev resources

Combined Approach: Modern cloud access control combines RBAC + ABAC + Tags for fine-grained control.


Q7. Explain the role of API gateway in secure cloud interface design.

Answer:

An API gateway is a controlled entry point between clients and backend cloud services. It reduces the exposure of internal services and enforces security policies.

Gateway Functions:

FunctionSecurity BenefitExample
AuthenticationVerifies identity before request processingJWT validation using identity provider public keys
AuthorizationChecks whether the caller may access the operationOnly finance role can call billing API
Rate limitingReduces brute force and denial-of-service riskMaximum 100 requests per minute per client
Input validationBlocks malformed or unexpected requestsReject request body that does not match schema
TLS/mTLSProtects data in transit and verifies endpointsClient certificate required for partner API
LoggingCreates evidence for monitoring and investigationLog request ID, caller, resource, and decision
TransformationRemoves unnecessary exposure of backend structureMap public API route to internal service route

Benefits:

  1. Centralized security enforcement
  2. Reduced attack surface
  3. Consistent policy application
  4. Better monitoring and logging
  5. Simplified client integration

Q8. What are the security risks of cloud bursting? Suggest suitable controls.

Answer:

Security Risks:

RiskExplanation
Policy inconsistencyBurst resources may not receive the same security policies
Data residency violationData may move to unauthorized regions
Weak credentialsTemporary resources may use weak or default credentials
Exposed portsManual configuration may expose unnecessary ports
Unapproved data transfersSensitive data may be moved without approval
Residual riskTemporary resources may not be properly decommissioned

Suitable Controls:

Control AreaRecommended Control
ConnectivityUse encrypted tunnels, private connectivity, IPsec VPN
IdentityUse federated identity and short-lived credentials
NetworkUse segmented subnets, security groups, firewalls
DataClassify data before bursting and encrypt replication
ConfigurationUse hardened images and infrastructure as code
MonitoringSend logs from both environments to a central SIEM
DecommissioningDestroy temporary resources, revoke tokens, wipe storage

Q9. Explain how secure on-premise internet access protects users and data.

Answer:

Secure on-premise internet access is the design pattern used to protect users, devices, and applications inside an organization when they access the internet, cloud services, or SaaS applications.

Protection Mechanisms:

ComponentPurposeSecurity Function
FirewallControls network trafficBlock unauthorized ports, protocols, destinations
Proxy / SWGInspects web trafficURL filtering, malware detection, TLS inspection
DNS SecurityBlocks malicious domainsPrevent command-and-control access
CASBMonitors cloud app usageDetect shadow IT, enforce SaaS DLP
DLPPrevents data leakageBlock confidential files to unapproved services
IDS/IPSDetects suspicious trafficIdentify exploitation attempts
SIEMCorrelates security logsAlert on abnormal activity
ZTNAGrants app-specific accessReplace broad VPN with application-level access

Secure Access Flow:

  1. User connects to enterprise network
  2. Identity and device posture verified
  3. DNS checked against threat intelligence
  4. Traffic passes through secure gateway
  5. Gateway applies URL filtering, malware inspection, DLP
  6. Approved traffic forwarded
  7. Logs sent to monitoring systems

Benefits:

  • Malware protection
  • Data loss prevention
  • User accountability
  • Cloud application control
  • Policy enforcement
  • Remote and branch support

Q10. What is a CASB? Explain its role in cloud application security.

Answer:

CASB (Cloud Access Security Broker) is a security control point that monitors and governs access to cloud applications. It sits between users and cloud services to enforce security policies.

Role in Cloud Application Security:

FunctionDescriptionExample
VisibilityDiscovers cloud apps in useIdentify sanctioned and unsanctioned SaaS
Shadow IT DetectionDetects unauthorized cloud usageAlert on personal Dropbox usage
Data Loss PreventionPrevents sensitive data leakageBlock upload of customer records to personal storage
ComplianceEnforces regulatory requirementsEnsure GDPR-compliant data handling
Threat ProtectionDetects malicious cloud activityBlock compromised accounts
Access ControlEnforces authentication and authorizationRequire MFA for cloud app access
EncryptionProtects data in cloud appsEncrypt sensitive files

Benefits:

  1. Centralized cloud app governance
  2. Visibility into cloud usage
  3. Data protection
  4. Compliance enforcement
  5. Threat detection
  6. Consistent policy application

Q11. Explain webhook security controls in external cloud integration.

Answer:

Webhooks are common in cloud integrations. They allow an external system to send event notifications to an enterprise endpoint. Since webhooks are exposed to external sources, they must be protected carefully.

Webhook Security Checklist:

  1. Accept requests only over HTTPS
  2. Verify provider signature using shared secret or public key
  3. Check timestamp to prevent replay attacks
  4. Validate request schema and event type
  5. Process webhook asynchronously through a queue
  6. Return minimal response information
  7. Log request ID, provider ID, event type, and decision

Webhook Attacks and Prevention:

AttackPrevention
Forged requestsSignature verification
Replay attacksTimestamp validation
InjectionSchema validation
Denial of serviceRate limiting, queue processing
Information disclosureMinimal response

Best Practices:

  • Use HTTPS only
  • Verify signatures
  • Validate timestamps
  • Process asynchronously
  • Log all requests
  • Monitor for anomalies

Q12. Explain the need for secure on-premise internet access.

Answer:

Even when workloads move to the cloud, many users still connect from offices, campuses, laboratories, or branch networks. Secure on-premise internet access protects these users.

Needs:

NeedExplanationExample
Malware protectionInternet downloads and malicious links can infect devicesBlock known malicious domains and scan files
Data loss preventionSensitive data may be uploaded to unauthorized servicesDetect and block customer records sent to personal storage
User accountabilityOrganizations need to know who accessed which site or serviceLog user, device, URL, time, and decision
Cloud application controlEmployees may use unsanctioned SaaS toolsMonitor and control shadow IT
Policy enforcementDifferent users need different access levelsAllow research sites for students but block risky downloads
Remote and branch supportUsers may work from multiple locationsUse cloud-delivered secure web gateway or ZTNA

Architecture Components:

  • Firewall
  • Proxy / Secure Web Gateway
  • DNS Security
  • CASB
  • DLP
  • IDS/IPS
  • SIEM
  • ZTNA

Q13. Explain the difference between full tunnel and split tunnel.

Answer:

ApproachDescriptionAdvantagesSecurity Concern
Full tunnelAll user traffic is routed through enterprise security controlsMaximum visibility and policy controlMay increase latency and gateway load
Split tunnelOnly selected traffic goes through enterprise controls; other internet traffic exits locallyBetter performance and reduced bandwidth costUninspected traffic may increase risk

Full Tunnel:

  • All traffic goes through enterprise security
  • Maximum visibility
  • Higher latency
  • Higher gateway load

Split Tunnel:

  • Only selected traffic goes through enterprise
  • Better performance
  • Reduced bandwidth cost
  • Some traffic uninspected

Cloud-Delivered Gateway:

  • Traffic inspected by security service close to user
  • Good for remote users and branches
  • Requires reliable identity and policy integration

Zero-Trust Access:

  • Access granted to specific applications
  • Limits lateral movement
  • Requires mature identity and device posture controls

Best Practice: Secure internet access should not depend only on network location. It should combine identity, device health, application sensitivity, data classification, and behaviour monitoring.


Q14. Explain the cloud bursting architecture in detail.

Answer:

A secure cloud bursting architecture contains:

Components:

  1. Private environment — Primary data centre where normal workload runs
  2. Public cloud environment — Temporary additional capacity
  3. Secure connectivity — VPN, private link, dedicated connection, encrypted tunnel
  4. Traffic management — Load balancer, DNS routing, global traffic manager
  5. Identity federation — Consistent authentication across environments
  6. Data synchronization — Replication with encryption and integrity checks
  7. Centralized monitoring — Logging and alerting for both components
  8. Automation templates — For creating and deleting burst resources securely

Security Controls:

Control AreaRecommended ControlPurpose
ConnectivityEncrypted tunnels, private connectivityProtect traffic
IdentityFederated identity, short-lived credentialsAvoid unmanaged accounts
NetworkSegmented subnets, security groupsLimit traffic exposure
DataClassify data, encrypt replicationPrevent unauthorized movement
ConfigurationHardened images, infrastructure as codeAvoid manual errors
MonitoringCentral SIEMDetect abnormal activity
DecommissioningDestroy resources, revoke tokensReduce residual risk

Workflow:

  1. Monitor load
  2. Trigger automation
  3. Apply security baseline
  4. Route traffic
  5. Synchronize data
  6. Monitor both environments
  7. Decommission resources

Q15. Explain secure external cloud integration.

Answer:

Secure external cloud integration is a design pattern for safely connecting an organization’s cloud environment with external systems such as SaaS platforms, partner APIs, payment gateways, and other cloud providers.

Types of Integration:

Integration TypeDescriptionExample
SaaS integrationEnterprise app connects to SaaSCRM, HRMS, email
Partner APIPartner exchanges dataPayment gateway
Cross-cloud integrationOne cloud communicates with anotherCloud A reads Cloud B
Identity federationExternal IdP authenticates usersB2B guest users
Webhook integrationExternal service sends callbackPayment notification
Data pipelineData moved to external processingCloud data warehouse
Marketplace serviceThird-party product deployedSecurity scanner

Security Design Principles:

  1. Approve through formal risk process
  2. Use standard protocols (OAuth 2.0, OIDC, SAML, TLS, mTLS)
  3. Use least-privilege scopes
  4. Never share root credentials
  5. Store secrets in managed vault
  6. Validate webhook signatures
  7. Encrypt data in transit and at rest
  8. Log all integration actions
  9. Define incident response procedures
  10. Review third-party security posture

Integration Security Layer:

  • API gateway
  • Token broker
  • Message queue
  • Schema validator
  • Secrets vault
  • Data filter
  • Audit pipeline

Q16. Explain the role of API gateway in secure cloud interface design.

Answer:

An API gateway is a controlled entry point between clients and backend cloud services. It reduces the exposure of internal services and enforces security policies.

Gateway Functions:

FunctionSecurity BenefitExample
AuthenticationVerifies identityJWT validation
AuthorizationChecks permissionsRole-based access
Rate limitingReduces brute force100 requests/minute
Input validationBlocks malformed requestsSchema validation
TLS/mTLSProtects data in transitClient certificate
LoggingCreates evidenceRequest ID logging
TransformationHides backend structureRoute mapping

Benefits:

  1. Centralized security enforcement
  2. Reduced attack surface
  3. Consistent policy application
  4. Better monitoring
  5. Simplified client integration

Common Threats Mitigated:

  • Broken object authorization
  • Excessive permissions
  • Credential exposure
  • Injection attacks
  • API abuse
  • Weak TLS
  • Poor logging

Q17. Explain the difference between CREATE and MERGE commands in Cypher with suitable examples.

Answer:

Note: This question relates to graph databases (Neo4j). In Cypher:

CREATE:

  • Always creates new nodes or relationships
  • Does not check if data exists
  • Can create duplicates
  • Example:
CREATE (p:Person {name: 'Alice', age: 25})
RETURN p;

Run twice → Two separate nodes (duplicates)

MERGE:

  • Creates only if not exists
  • If exists, matches existing
  • Prevents duplicates
  • Example:
MERGE (p:Person {name: 'Alice', age: 25})
RETURN p;

Run twice → Only one node created

AspectCREATEMERGE
BehaviourAlways createsCreates only if not exists
Duplicate DataCan create duplicatesPrevents duplicates
Use CaseAlways create newEnsure uniqueness
Repeated ExecutionMultiple identical nodesSingle node

Key Takeaway: Use CREATE when you want to always create. Use MERGE when you want to create only if it doesn’t exist.


Q18. Explain the Cache-Aside (Lazy Loading) strategy.

Answer:

Cache-Aside Strategy (Lazy Loading): The application is responsible for loading data into the cache. Data is fetched from the cache first; if not found, it is loaded from the database and then stored in the cache for future requests.

How It Works:

  1. Application checks the cache for data
  2. If found (cache hit), return directly from cache
  3. If not found (cache miss), fetch from database
  4. Store in cache (with TTL) and return to client

Read Flow (Cache Miss):

Client → Application → Redis Cache → (not found) → Database
                ↓
           Store in cache (with TTL)
                ↓
           Return data to client

Read Flow (Cache Hit):

Client → Application → Redis Cache → (found) → Return data (fast response)

Write Flow:

Application → Update database → Invalidate/delete cache entry

Example — E-commerce Product Details: When a user views a product (e.g., product ID 101), the application first checks Redis. If not found, it fetches from the database, stores in Redis (e.g., for 5 minutes), and returns it.

Benefits:

  1. Reduces database load
  2. Improves application performance
  3. Simple to implement
  4. Works well for read-heavy applications
  5. Gives control to the application

Considerations:

  1. First request is slower (cache miss)
  2. Need to handle cache invalidation
  3. Possibility of stale data
  4. Choose appropriate TTL

Q19. Explain the key terms in Apache Cassandra.

Answer:

Apache Cassandra is a distributed wide-column NoSQL database.

Key Terms:

TermDefinition
NodeA single instance of Cassandra running on a machine. Each node stores a portion of the data. Nodes are equal (no master/slave).
ClusterA group of nodes that work together to store and manage data. All nodes are peer-to-peer. Provides high availability and scalability.
KeyspaceA top-level container (similar to a database). Defines replication settings and contains one or more tables.
PartitionA subset of data identified by a partition key. Rows with the same partition key are stored together.
Replication FactorThe number of copies of each partition stored across different nodes. RF=3 means 3 copies of each partition.

Data Model Hierarchy:

Cluster → Keyspace → Table

CQL Commands:

-- Create keyspace
CREATE KEYSPACE university
WITH replication = {
    'class': 'SimpleStrategy',
    'replication_factor': 3
};

-- Use keyspace
USE university;

-- Create table
CREATE TABLE students (
    student_id int,
    name text,
    department text,
    age int,
    PRIMARY KEY (student_id)
);

Benefits:

  • High availability
  • Fault tolerance
  • Horizontal scalability
  • No single point of failure

Q20. Explain the Property Graph Model.

Answer:

The property graph model is a graph data model in which data is represented using nodes and relationships, and both nodes and relationships can have properties in the form of key-value pairs.

Components:

ComponentDescriptionExample
NodesRepresent entities or objectsPerson, Product, Company
LabelsIdentify the type or category of a node:Person, :Course
Relationship TypesDescribe the nature of connectionENROLLED_IN, FRIEND_OF
PropertiesKey-value pairs storing information{name: "Alice", age: 25}

Example — University Graph:

:Student (Alice)                    :Course (NoSQL)
{id: 1, name: "Alice", age: 20}     {id: 101, name: "NoSQL", credits: 4}
      │                                     │
      │ ENROLLED_IN (year: 2026)            │ TAUGHT_BY (semester: "Fall 2026")
      └─────────────────────────────────────┘
      │                                     │
      │ WORKS_AT (since: 2023)              │
      ↓                                     ↓
:Company (ABC Corp)                 :Teacher (Dr. Kumar)
{id: 201, name: "ABC Corp",         {id: 301, name: "Dr. Kumar",
 industry: "IT"}                     department: "CSE"}

Legend:

  • ○ = Node
  • → = Relationship (with direction)
  • {…} = Properties
  • :Label = Node label

Key Takeaway: Labels tell us what a node is, while relationship types tell us how two nodes are connected.

Cypher Example:

CREATE (a:Student {id: 1, name: 'Alice', age: 20})
CREATE (c:Course {id: 101, name: 'NoSQL', credits: 4})
CREATE (a)-[:ENROLLED_IN {year: 2026}]->(c)

SECTION C: ANALYTICAL QUESTIONS (10)


Q1. Analyze the following scenario and recommend appropriate cloud security design patterns.

Scenario: A university hosts its student portal on private infrastructure. During admission and examination result days, the portal receives heavy traffic. The university also uses a third-party payment gateway, a cloud-based email service, and a student document storage service. Students and staff access the portal from campus, home, and mobile networks.

Answer:

Recommended Design Patterns:

PatternReason
Cloud BurstingHandle peak traffic during admission/result days without permanent hardware
Secure Cloud InterfacesProtect APIs and portals used by students, staff, and payment gateway
Cloud Resource Access ControlDefine access rules for students, faculty, administrators, and service accounts
Geo-TaggingEnsure student records, payment logs, and backups comply with data residency
Secure On-Premise Internet AccessProtect users accessing the portal from campus and home
Secure External Cloud IntegrationSecurely integrate payment gateway, email service, and storage service

Cloud Bursting Architecture:

Private Infrastructure → Secure Connectivity → Public Cloud Burst
        ↓                          ↓                    ↓
   Load Balancer ←────────── VPN/Tunnel ──────────→ Load Balancer
        ↓                                              ↓
   Private Servers                              Cloud Instances

Access Control Rules:

RoleAccess
StudentsView results, pay fees, access documents
FacultyManage courses, view student data
AdministratorsFull access (with MFA)
Service accountsPayment gateway, email, storage (scoped)

Geo-Tagging Policy:

ObjectGeo-Tag
Student recordscountry=India, residency=India
Payment logscountry=India, class=PII
Backupsbackup_location=approved_region

External Integration Checklist:

  • Use OAuth 2.0 for payment gateway
  • Validate webhook signatures
  • Store secrets in vault
  • Encrypt data in transit and at rest
  • Log all integration actions
  • Review third-party security posture

Q2. Analyze the security risks of cloud bursting and propose controls.

Answer:

Scenario: An e-commerce company runs most workloads in a private cloud but experiences high traffic during festival sales. They want to use cloud bursting.

Security Risks:

RiskExplanation
Policy inconsistencyBurst resources may not receive same security policies
Data residency violationData may move to unauthorized regions
Weak credentialsTemporary resources may use weak credentials
Exposed portsManual configuration may expose ports
Unapproved data transfersSensitive data may be moved without approval
Residual riskResources may not be decommissioned

Proposed Controls:

Control AreaControl
ConnectivityUse encrypted tunnels, private connectivity, IPsec VPN
IdentityUse federated identity and short-lived credentials
NetworkUse segmented subnets, security groups, firewalls
DataClassify data before bursting, encrypt replication
ConfigurationUse hardened images and infrastructure as code
MonitoringSend logs from both environments to central SIEM
DecommissioningDestroy resources, revoke tokens, wipe storage

Workflow:

  1. Monitor load during festival sales
  2. Trigger automation when threshold reached
  3. Apply security baseline (IAM, network, encryption, logging)
  4. Route traffic to cloud instances
  5. Synchronize only approved data
  6. Monitor both environments
  7. Decommission after peak

Benefits:

  • Handle peak traffic without permanent hardware
  • Cost optimization
  • Business continuity
  • Geographic reach

Q3. Analyze how geo-tagging, encryption, logging, and access control can be used to protect patient data in a hospital cloud.

Answer:

Scenario: A hospital stores patient data in the cloud and must ensure records do not leave approved regions.

Solution Using Geo-Tagging, Encryption, Logging, and Access Control:

1. Geo-Tagging:

  • Tag patient records with country=India, region=ap-south
  • Tag backups with backup_location=approved_region
  • Policy engine blocks movement to unapproved regions
  • Audit logs prove records never left approved jurisdictions

2. Encryption:

  • Encrypt data at rest (AES-256)
  • Encrypt data in transit (TLS 1.3)
  • Encrypt replication traffic
  • Use customer-managed keys (CMK)
  • Key rotation policy

3. Logging:

  • Log every access to patient records
  • Log every movement of data
  • Log every denied request
  • Send logs to central SIEM
  • Preserve audit trails for compliance

4. Access Control:

  • Use RBAC: Doctors, Nurses, Admins, Auditors
  • Use ABAC: Allow access only if department=user.department
  • Use tag-based access: environment=production
  • Apply least privilege
  • Use just-in-time access for admins
  • Regular access reviews

Combined Protection:

Patient Data → Geo-Tag → Policy Engine → Allow/Deny
                    ↓
              Encryption → TLS/AES
                    ↓
              Logging → SIEM
                    ↓
              Access Control → RBAC/ABAC

Benefits:

  • Data residency compliance
  • Data protection
  • Auditability
  • Access control
  • Incident response

Q4. Analyze the security controls needed for a startup exposing APIs to mobile apps and partner vendors.

Answer:

Scenario: A startup exposes APIs to mobile apps and partner vendors.

Secure Cloud Interface Pattern:

Mobile Apps → API Gateway → AuthN/AuthZ → Cloud Services
Partner Vendors → API Gateway → AuthN/AuthZ → Cloud Services

Controls:

ControlImplementation
AuthenticationOAuth 2.0 / OIDC for mobile apps; mTLS for partners
AuthorizationRole-based scopes; partner-specific permissions
Rate Limiting100 requests/minute per client; burst protection
Input ValidationSchema validation; reject malformed requests
TLS/mTLSTLS 1.3 for mobile; mTLS for partners
LoggingLog request ID, caller, resource, decision
WAFBlock injection, XSS, bot attacks
Secrets ManagementVault for API keys, certificates
MonitoringSIEM alerts on anomalies

API Gateway Functions:

  • Authentication (JWT validation)
  • Authorization (role checks)
  • Rate limiting (per client)
  • Input validation (schema)
  • TLS termination
  • Logging (audit)
  • Transformation (hide backend)

Partner Onboarding:

  1. Risk assessment
  2. Data classification
  3. Scope definition (least privilege)
  4. Contract with data limits
  5. mTLS certificate issuance
  6. Monitoring setup
  7. Regular review

Threats Mitigated:

  • Broken object authorization
  • Excessive permissions
  • Credential exposure
  • Injection attacks
  • API abuse
  • Weak TLS
  • Poor logging

Q5. Analyze the secure on-premise and remote internet access pattern for employees accessing SaaS applications from campus and home.

Answer:

Scenario: Employees access SaaS applications from campus and home.

Recommended Pattern:

On-prem users → SWG/Proxy → Firewall/IDS/DLP → Internet + SaaS
     ↓              ↓              ↓                ↓
 DNS Security   URL Filtering  Malware Insp.   CASB Rules
                TLS Inspection  User Logs       Zero Trust

Components:

ComponentPurposeSecurity Function
FirewallControl trafficBlock unauthorized ports
SWG/ProxyInspect web trafficURL filtering, malware detection
DNS SecurityBlock malicious domainsPrevent C2 access
CASBMonitor cloud appsDetect shadow IT, enforce DLP
DLPPrevent data leakageBlock confidential uploads
IDS/IPSDetect threatsIdentify exploitation
SIEMCorrelate logsAlert on anomalies
ZTNAApp-specific accessReplace broad VPN

Access Flow:

  1. User connects (campus or home)
  2. Identity and device posture verified
  3. DNS checked against threat intelligence
  4. Traffic passes through secure gateway
  5. Gateway applies URL filtering, malware inspection, DLP
  6. Approved traffic forwarded
  7. Logs sent to SIEM

Tunnel Approaches:

ApproachUse Case
Full tunnelMaximum visibility (campus)
Split tunnelBetter performance (home)
Cloud-delivered gatewayRemote users, branches
Zero-trust accessApp-specific access

Benefits:

  • Malware protection
  • Data loss prevention
  • User accountability
  • Cloud application control
  • Policy enforcement
  • Remote support

Best Practice: Combine identity, device health, application sensitivity, data classification, and behaviour monitoring.


Q6. Analyze the secure integration checklist for a college portal integrating with an external payment gateway using webhooks.

Answer:

Scenario: A college portal integrates with an external payment gateway using webhooks.

Secure Integration Checklist:

1. Authentication & Authorization:

  • Use OAuth 2.0 / OIDC for API access
  • Use least-privilege scopes
  • Never share root credentials
  • Store API keys in managed vault

2. Webhook Security:

  • Accept requests only over HTTPS
  • Verify provider signature (shared secret or public key)
  • Check timestamp to prevent replay attacks
  • Validate request schema and event type
  • Process webhook asynchronously through a queue
  • Return minimal response information
  • Log request ID, provider ID, event type, decision

3. Data Protection:

  • Encrypt data in transit (TLS 1.3)
  • Encrypt data at rest (AES-256)
  • Minimize data shared (only order ID, amount)
  • Do not send full customer profile

4. Secrets Management:

  • Store secrets in managed vault
  • Rotate keys regularly
  • Use automated scanning for leaks
  • Never store secrets in code or logs

5. Monitoring & Logging:

  • Log all integration actions
  • Monitor for abnormal usage
  • Alert on suspicious activity
  • Send logs to SIEM

6. Third-Party Risk:

  • Review payment gateway security posture
  • Check compliance reports (PCI DSS)
  • Define incident response procedures
  • Define exit/offboarding process

7. Integration Security Layer:

College Portal → API Gateway → Token Broker → Payment Gateway
                      ↓
                Secrets Vault
                      ↓
                Audit Pipeline

Webhook Attack Prevention:

AttackPrevention
Forged requestsSignature verification
Replay attacksTimestamp validation
InjectionSchema validation
DoSRate limiting, queue
Info disclosureMinimal response

Q7. Analyze the access control requirements for a developer needing access to a development database but not production customer records.

Answer:

Scenario: A developer needs access to a development database but must not access production customer records.

Access Control Solution:

Access Rule:

Subject: user in group = Developers
Action: read/write database records
Resource condition: tag environment = development
Network condition: access from corporate VPN or trusted device

Combined Approach:

ModelImplementation
RBACAssign role Developer
ABACAllow if department=user.department and device compliant
Tag-basedResource tag environment=development
Just-in-timeTemporary access for specific tasks
Policy-basedCentral policy denies production access

Policy Decision:

IF user.role = Developer
AND resource.tag.environment = development
AND network = corporate VPN
AND device = compliant
THEN allow
ELSE deny

Components:

ComponentRole
Identity ProviderAuthenticate developer
Policy Decision PointEvaluate request
Policy Enforcement PointEnforce decision
Policy Information PointProvide context (device, location, tags)
Audit SystemRecord decisions
Secrets ManagerStore credentials

Mistakes to Avoid:

  • Using root account
  • Permanent admin roles
  • Wildcard permissions
  • Direct user permissions
  • Unrotated access keys
  • No access review
  • No deny guardrails

Benefits:

  • Least privilege
  • Separation of duties
  • Auditability
  • Risk reduction
  • Compliance

Q8. Analyze the security architecture for a hybrid college portal using cloud bursting, geo-tagging, and external integration.

Answer:

Scenario: A college hosts its student portal on private infrastructure. During admission and result days, traffic spikes. The college uses a payment gateway, cloud email, and document storage.

Security Architecture:

┌─────────────────────────────────────────────────────────────┐
│                    COLLEGE PORTAL                            │
├─────────────────────────────────────────────────────────────┤
│  Private Infrastructure          │  Public Cloud Burst      │
│  ┌─────────────┐                │  ┌─────────────┐         │
│  │ Web Servers │←── VPN/Tunnel ──│─→│ Cloud       │         │
│  │ Database    │                │  │ Instances   │         │
│  └─────────────┘                │  └─────────────┘         │
│         ↓                       │         ↓                │
│  ┌─────────────┐                │  ┌─────────────┐         │
│  │ Load        │←───────────────│─→│ Load        │         │
│  │ Balancer    │                │  │ Balancer    │         │
│  └─────────────┘                │  └─────────────┘         │
├─────────────────────────────────────────────────────────────┤
│  Identity Federation (SSO, MFA)                             │
├─────────────────────────────────────────────────────────────┤
│  Geo-Tagging Policy Engine                                  │
│  - Student records: country=India, residency=India          │
│  - Payment logs: class=PII, country=India                   │
│  - Backups: backup_location=approved_region                 │
├─────────────────────────────────────────────────────────────┤
│  External Integrations                                      │
│  ┌─────────────┐  ┌─────────────┐  ┌─────────────┐        │
│  │ Payment     │  │ Email       │  │ Document    │        │
│  │ Gateway     │  │ Service     │  │ Storage     │        │
│  └─────────────┘  └─────────────┘  └─────────────┘        │
│         ↓                ↓                ↓                │
│  ┌─────────────────────────────────────────────────┐       │
│  │ Integration Security Layer                       │       │
│  │ API Gateway | Token Broker | Secrets Vault       │       │
│  │ Schema Validator | Audit Pipeline                │       │
│  └─────────────────────────────────────────────────┘       │
└─────────────────────────────────────────────────────────────┘

Components:

ComponentPurpose
Cloud BurstingHandle peak traffic
Geo-TaggingData residency compliance
Secure InterfacesProtect APIs and portals
Access ControlRBAC/ABAC for users
External IntegrationSecure payment, email, storage

Access Control Rules:

RoleAccess
StudentsView results, pay fees
FacultyManage courses
AdminsFull access (MFA)
ServicesScoped access

Security Controls:

  1. Cloud bursting: VPN, IAM, data classification, SIEM
  2. Geo-tagging: Mandatory tags, region restrictions
  3. Interfaces: API gateway, MFA, OAuth, WAF
  4. Access control: RBAC, ABAC, least privilege
  5. Integration: mTLS, scopes, vault, webhook validation

Q9. Analyze the role of CASB in cloud application security for a university.

Answer:

Scenario: A university wants to monitor and govern cloud application usage by students and staff.

CASB (Cloud Access Security Broker) Role:

FunctionDescriptionExample
VisibilityDiscover cloud apps in useIdentify sanctioned/unsanctioned SaaS
Shadow IT DetectionDetect unauthorized cloud usageAlert on personal Dropbox
Data Loss PreventionPrevent sensitive data leakageBlock student records to personal storage
ComplianceEnforce regulatory requirementsGDPR, FERPA compliance
Threat ProtectionDetect malicious cloud activityBlock compromised accounts
Access ControlEnforce authenticationRequire MFA for cloud apps
EncryptionProtect data in cloud appsEncrypt sensitive files

Deployment:

Users → CASB → Cloud Apps (SaaS)
         ↓
    Policy Engine
         ↓
    DLP / Threat Protection
         ↓
    Logging / SIEM

Benefits:

  1. Centralized cloud app governance
  2. Visibility into cloud usage
  3. Data protection
  4. Compliance enforcement
  5. Threat detection
  6. Consistent policy application

Use Cases:

  • Monitor student email usage
  • Block unauthorized file sharing
  • Enforce MFA for cloud apps
  • Detect compromised accounts
  • Prevent data leakage
  • Ensure compliance

Integration with Other Controls:

  • SWG for web traffic inspection
  • DLP for data protection
  • SIEM for log correlation
  • ZTNA for app-specific access

Q10. Analyze the complete security design for a hospital cloud using all patterns.

Answer:

Scenario: A hospital stores patient data in the cloud and must ensure records do not leave approved regions.

Complete Security Design:

1. Cloud Bursting:

  • Private hospital servers for normal load
  • Public cloud burst for peak (e.g., pandemic)
  • Secure connectivity (VPN)
  • Identity federation
  • Data classification before bursting
  • Central SIEM

2. Geo-Tagging:

  • Patient records: country=India, region=ap-south
  • Backups: backup_location=approved_region
  • Policy engine blocks unapproved regions
  • Audit logs prove compliance

3. Secure Cloud Interfaces:

  • API gateway for EMR APIs
  • MFA for doctors/nurses
  • OAuth 2.0 for mobile apps
  • Rate limiting
  • Input validation
  • TLS 1.3
  • Logging

4. Cloud Resource Access Control:

  • RBAC: Doctors, Nurses, Admins, Auditors
  • ABAC: department=user.department
  • Tag-based: environment=production
  • Least privilege
  • Just-in-time for admins
  • Access reviews

5. Secure On-Premise Internet Access:

  • Firewall
  • SWG/Proxy
  • DNS Security
  • CASB
  • DLP
  • SIEM
  • ZTNA

6. Secure External Cloud Integration:

  • Integration security layer
  • API gateway
  • Token broker
  • Secrets vault
  • Schema validator
  • Audit pipeline
  • Webhook validation

Architecture:

┌─────────────────────────────────────────────────────────────┐
│                    HOSPITAL CLOUD                            │
├─────────────────────────────────────────────────────────────┤
│  Private Infrastructure          │  Public Cloud Burst      │
│  ┌─────────────┐                │  ┌─────────────┐         │
│  │ EMR Servers │←── VPN/Tunnel ──│─→│ Cloud       │         │
│  │ Database    │                │  │ Instances   │         │
│  └─────────────┘                │  └─────────────┘         │
├─────────────────────────────────────────────────────────────┤
│  Identity Federation (SSO, MFA)                             │
├─────────────────────────────────────────────────────────────┤
│  Geo-Tagging Policy Engine                                  │
│  - Patient records: country=India, residency=India          │
│  - Backups: backup_location=approved_region                 │
├─────────────────────────────────────────────────────────────┤
│  Access Control: RBAC + ABAC + Tags                         │
├─────────────────────────────────────────────────────────────┤
│  Secure Interfaces: API Gateway, WAF, OAuth                 │
├─────────────────────────────────────────────────────────────┤
│  External Integrations: Payment, Insurance, Labs            │
│  ┌─────────────────────────────────────────────────┐       │
│  │ Integration Security Layer                       │       │
│  │ API Gateway | Token Broker | Secrets Vault       │       │
│  │ Schema Validator | Audit Pipeline                │       │
│  └─────────────────────────────────────────────────┘       │
├─────────────────────────────────────────────────────────────┤
│  Secure On-Premise Internet Access                          │
│  Firewall | SWG | DNS | CASB | DLP | SIEM | ZTNA            │
└─────────────────────────────────────────────────────────────┘

Compliance:

  • HIPAA compliance
  • Data residency (India)
  • Audit trails
  • Access controls
  • Encryption

Benefits:

  • Data protection
  • Regulatory compliance
  • High availability
  • Scalability
  • Security

SUMMARY TABLE

SectionCountTopics Covered
MCQ50Design patterns, cloud bursting, geo-tagging, secure interfaces, access control, internet access, external integration
Theory20Design pattern definition, structure, cloud bursting, geo-tagging, secure interfaces, RBAC/ABAC, API gateway, risks, CASB, webhooks, internet access, tunnels, architecture, external integration, CREATE/MERGE, Cache-Aside, Cassandra, Property Graph
Analytical10University portal scenario, cloud bursting risks, hospital data protection, startup API security, SaaS access, payment gateway integration, developer access, hybrid college portal, CASB for university, complete hospital design

On this page