SPC Unit 3: Questions & Answers
Unit 3: Cloud Security Design Patterns -> Generated and Prepared By Thiruselvan (ThiruXD)
Introduction to Design Patterns
Q1. What is a design pattern?
- A random diagram
- A reusable solution to a recurring design problem
- A software license
- A cloud pricing model
Answer: B) A reusable solution to a recurring design problem -> Explanation: A design pattern is a proven and reusable solution to a recurring design problem. In cloud security, design patterns help teams apply security consistently across different workloads, applications, networks, and data flows.
Q2. Which of the following is NOT a reason for using security design patterns?
- Consistency
- Scalability
- Increasing cloud cost
- Auditability
Answer: C) Increasing cloud cost -> Explanation: Security design patterns provide consistency, scalability, auditability, risk reduction, and communication. They do not increase cloud cost; in fact, they can optimize costs.
Q3. Which pattern element states the recurring issue that must be solved?
- Context
- Problem
- Forces
- Solution
Answer: B) Problem -> Explanation: The Problem element states the recurring issue that must be solved. Example: Users need secure access to cloud APIs from different locations.
Q4. Which pattern element lists competing requirements and constraints?
- Problem
- Context
- Forces
- Controls
Answer: C) Forces -> Explanation: Forces list competing requirements and constraints such as security, performance, cost, latency, compliance, and user convenience.
Q5. Which pattern element defines how to test the pattern?
- Controls
- Benefits
- Risks
- Verification
Answer: D) Verification -> Explanation: Verification defines how to test the pattern, such as access tests, penetration tests, log reviews, and policy simulation.
Q6. Which category of design patterns controls who or what can access resources?
- Network security patterns
- Identity and access patterns
- Data protection patterns
- Interface security patterns
Answer: B) Identity and access patterns -> Explanation: Identity and access patterns control who or what can access resources. Examples include RBAC, ABAC, MFA, SSO, and identity federation.
Q7. Which category of design patterns protects APIs, portals, CLIs, and SDKs?
- Identity and access patterns
- Network security patterns
- Interface security patterns
- Data protection patterns
Answer: C) Interface security patterns -> Explanation: Interface security patterns protect APIs, portals, CLIs, SDKs, and service endpoints. Examples include API gateway, WAF, OAuth/OIDC, and rate limiting.
Q8. Which category of design patterns governs connections to third-party cloud and SaaS providers?
- Hybrid integration patterns
- External integration patterns
- Network security patterns
- Data protection patterns
Answer: B) External integration patterns -> Explanation: External integration patterns govern connections to third-party cloud and SaaS providers. Examples include webhook verification, partner API scopes, and cross-tenant access review.
Cloud Bursting
Q9. What is cloud bursting?
- Deleting cloud resources
- Expanding capacity during demand spikes
- Disabling network access
- Replacing all security controls
Answer: B) Expanding capacity during demand spikes -> Explanation: Cloud bursting is a hybrid cloud pattern where an application runs mainly in a private environment but expands into a public cloud during demand spikes.
Q10. Which of the following is a security concern for cloud bursting?
- Burst resources must receive the same security policies
- Temporary resources should be removed securely
- Data residency and privacy rules must be respected
- All of the above
Answer: D) All of the above -> Explanation: All are security concerns: burst resources must receive the same security policies, temporary resources should be removed securely, and data residency and privacy rules must be respected.
Q11. Which component provides secure connectivity in cloud bursting?
- Load balancer
- VPN, private link, or encrypted tunnel
- API gateway
- Firewall
Answer: B) VPN, private link, or encrypted tunnel -> Explanation: Secure connectivity in cloud bursting uses VPN, private link, dedicated connection, or encrypted tunnel to protect traffic between on-premise and cloud.
Q12. What is the first step in the cloud bursting workflow?
- Deploy cloud resources
- Monitor application load
- Route traffic
- Decommission resources
Answer: B) Monitor application load -> Explanation: The first step is to monitor application load, response time, and resource utilization in the private environment.
Q13. What should be done after peak load ends in cloud bursting?
- Keep resources running
- Decommission resources and revoke access
- Disable logs
- Remove security policies
Answer: B) Decommission resources and revoke access -> Explanation: After peak load ends, drain sessions, remove public cloud resources, archive logs, and revoke temporary access to reduce residual risk.
Q14. Which security control is used for data in cloud bursting?
- Classify data before bursting and encrypt replication
- Share all data with public cloud
- Disable encryption
- Use public storage
Answer: A) Classify data before bursting and encrypt replication -> Explanation: Classify data before bursting and encrypt replication traffic to prevent sensitive data from moving to unauthorized regions.
Q15. Which of the following is an advantage of cloud bursting?
- Improves elasticity without permanent hardware investment
- Increases permanent hardware cost
- Eliminates all security risks
- Removes need for monitoring
Answer: A) Improves elasticity without permanent hardware investment -> Explanation: Cloud bursting improves elasticity without permanent hardware investment. It supports seasonal and event-based traffic spikes.
Geo-Tagging
Q16. What is geo-tagging in cloud security?
- Changing file names
- Attaching location-based metadata to data and resources
- Increasing screen resolution
- Removing encryption
Answer: B) Attaching location-based metadata to data and resources -> Explanation: Geo-tagging is the process of adding geographic or location-based metadata to cloud data, users, devices, workloads, logs, or resources.
Q17. Geo-tagging helps with:
- Data residency and location-aware policy
- Screen resolution
- File compression
- Password management
Answer: A) Data residency and location-aware policy -> Explanation: Geo-tagging helps enforce policies related to data residency, regional compliance, access location, backup placement, disaster recovery, and privacy.
Q18. Which geo-tag would be used for a data object?
- country=India, region=ap-south
- name=Alice
- age=25
- role=admin
Answer: A) country=India, region=ap-south -> Explanation: Geo-tags for a data object include country and region, such as country=India, region=ap-south. These prevent unauthorized cross-border transfer.
Q19. Which risk is associated with geo-tagging?
- Incorrect tags
- Location spoofing
- Tag bypass
- All of the above
Answer: D) All of the above -> Explanation: Risks include incorrect tags, location spoofing, privacy risk, tag bypass, compliance drift, and replication mismatch.
Q20. What is the control for incorrect tags?
- Use automated tagging and mandatory tag policies
- Manual tagging
- Ignore tags
- Delete all tags
Answer: A) Use automated tagging and mandatory tag policies -> Explanation: The control for incorrect tags is to use automated tagging and mandatory tag policies to prevent manual tagging errors.
Q21. Which use case of geo-tagging ensures data remains within approved legal jurisdictions?
- Data residency
- Access control
- Disaster recovery
- Cost and performance
Answer: A) Data residency -> Explanation: Data residency ensures data remains within approved legal jurisdictions. Example: Customer data stored only in Indian cloud regions.
Q22. Which geo-tagging use case helps investigators identify where data moved and who accessed it?
- Data residency
- Incident response
- Cost and performance
- Legal compliance
Answer: B) Incident response -> Explanation: Incident response helps investigators identify where data moved and who accessed it. Logs show access from abnormal location.
Secure Cloud Interfaces
Q23. Which component commonly protects APIs through authentication, rate limiting, and request validation?
- API gateway
- Spreadsheet
- Printer
- Unmanaged file share
Answer: A) API gateway -> Explanation: An API gateway is a controlled entry point that enforces authentication, authorization, rate limiting, TLS termination, request validation, and logging.
Q24. Which of the following is a type of cloud interface?
- Management console
- REST API
- CLI
- All of the above
Answer: D) All of the above -> Explanation: Cloud interfaces include management consoles, REST APIs, CLIs, SDKs, service endpoints, automation pipelines, and webhooks.
Q25. Which security requirement applies to a management console?
- MFA, SSO, conditional access, audit logging
- No authentication
- Public access
- Plain HTTP
Answer: A) MFA, SSO, conditional access, audit logging -> Explanation: Management consoles require MFA, SSO, conditional access, and audit logging to protect administrative access.
Q26. Which protocol is used for secure API authentication?
- OAuth/OIDC
- FTP
- Telnet
- HTTP
Answer: A) OAuth/OIDC -> Explanation: OAuth/OIDC is used for secure API authentication. It provides token-based access control.
Q27. What is the role of rate limiting in API security?
- Increases brute force risk
- Reduces brute force and denial-of-service risk
- Disables authentication
- Removes logging
Answer: B) Reduces brute force and denial-of-service risk -> Explanation: Rate limiting reduces brute force and denial-of-service risk by limiting the number of requests per client.
Q28. Which threat involves a user changing an object ID to access another user’s data?
- Broken object authorization
- Excessive permissions
- Credential exposure
- Injection attacks
Answer: A) Broken object authorization -> Explanation: Broken object authorization occurs when a user changes an object ID to access another user’s data. Mitigation: Check authorization for every object access.
Q29. Which threat involves secrets stored in source code or logs?
- Broken object authorization
- Credential exposure
- API abuse
- Weak TLS
Answer: B) Credential exposure -> Explanation: Credential exposure occurs when secrets are stored in source code or logs. Mitigation: Use secret vaults and scanning.
Q30. Which security control helps reduce API abuse?
- Rate limiting
- Unrestricted tokens
- Public storage
- Disabled authentication
Answer: A) Rate limiting -> Explanation: Rate limiting helps reduce API abuse by limiting the number of requests a client can make in a given time period.
Cloud Resource Access Control
Q31. What does RBAC stand for?
- Resource Backup and Copy
- Role-Based Access Control
- Regional Business Accounting Code
- Remote Binary Access Channel
Answer: B) Role-Based Access Control -> Explanation: RBAC stands for Role-Based Access Control. Access is based on assigned roles, such as DatabaseAdmin can manage database instances.
Q32. What does ABAC stand for?
- Attribute-Based Access Control
- Automated Backup and Copy
- Advanced Binary Access Code
- Application-Based Access Control
Answer: A) Attribute-Based Access Control -> Explanation: ABAC stands for Attribute-Based Access Control. Access is based on attributes of user, resource, action, and context.
Q33. Which access control model uses resource tags in policy conditions?
- RBAC
- ABAC
- Tag-based access
- Just-in-time access
Answer: C) Tag-based access -> Explanation: Tag-based access uses resource tags in policy conditions. Example: Developers can start resources tagged environment=dev.
Q34. What is the principle of least privilege?
- Give all users administrator access
- Give only the minimum required permissions
- Disable all logs
- Use the same password everywhere
Answer: B) Give only the minimum required permissions -> Explanation: Least privilege is a security principle that gives users and services only the minimum permissions required to perform their work.
Q35. Which component evaluates whether a request should be allowed?
- Policy Decision Point
- Policy Enforcement Point
- Policy Administration Point
- Policy Information Point
Answer: A) Policy Decision Point -> Explanation: The Policy Decision Point evaluates whether a request should be allowed. Example: IAM policy engine.
Q36. Which component enforces the allow or deny decision?
- Policy Decision Point
- Policy Enforcement Point
- Policy Administration Point
- Policy Information Point
Answer: B) Policy Enforcement Point -> Explanation: The Policy Enforcement Point enforces the allow or deny decision. Example: API gateway, proxy, storage service, firewall.
Q37. What is just-in-time access?
- Permanent admin roles
- Privileges granted temporarily when needed
- No access control
- Shared credentials
Answer: B) Privileges granted temporarily when needed -> Explanation: Just-in-time access grants privileges temporarily when needed. Example: Admin role activated for one hour after approval.
Q38. Which is a dangerous access control mistake?
- Using named admin roles
- Using root or owner account for daily work
- Performing access reviews
- Using just-in-time access
Answer: B) Using root or owner account for daily work -> Explanation: Using root or owner account for daily work is dangerous because a compromise gives full control. Better practice: Use named admin roles with MFA and auditing.
Q39. Which is a control for unrotated access keys?
- Use short-lived credentials and rotation
- Keep keys forever
- Share keys publicly
- Store keys in code
Answer: A) Use short-lived credentials and rotation -> Explanation: Unrotated access keys are dangerous because stolen keys remain useful for long periods. Control: Use short-lived credentials and rotation.
Secure On-Premise Internet Access
Q40. Which tool is commonly used to monitor and govern cloud application usage?
- CASB
- Compiler
- Image editor
- Text editor
Answer: A) CASB -> Explanation: CASB (Cloud Access Security Broker) is a security control point that monitors and governs access to cloud applications. It detects shadow IT and enforces SaaS DLP policies.
Q41. Which component inspects web traffic before it reaches the internet?
- Proxy / Secure Web Gateway
- Printer
- Spreadsheet
- Compiler
Answer: A) Proxy / Secure Web Gateway -> Explanation: A Proxy / Secure Web Gateway inspects web traffic before it reaches the internet. It performs URL filtering, malware detection, and TLS inspection.
Q42. Which component blocks malicious domains before connection occurs?
- DNS Security
- Firewall
- DLP
- SIEM
Answer: A) DNS Security -> Explanation: DNS Security blocks malicious domains before connection occurs. It prevents command-and-control domain access.
Q43. Which component prevents leakage of sensitive data?
- DLP
- Firewall
- Proxy
- IDS
Answer: A) DLP -> Explanation: DLP (Data Loss Prevention) prevents leakage of sensitive data. It blocks confidential files uploaded to unapproved services.
Q44. What is the difference between full tunnel and split tunnel?
- Full tunnel routes all traffic through enterprise controls; split tunnel routes selected traffic
- Full tunnel is faster; split tunnel is slower
- Full tunnel has no security; split tunnel has security
- Full tunnel is for remote users only
Answer: A) Full tunnel routes all traffic through enterprise controls; split tunnel routes selected traffic -> Explanation: Full tunnel routes all user traffic through enterprise security controls (maximum visibility). Split tunnel routes only selected traffic through enterprise controls (better performance).
Q45. Which approach grants access to specific applications rather than broad network access?
- Full tunnel
- Split tunnel
- Zero-trust access
- VPN
Answer: C) Zero-trust access -> Explanation: Zero-trust access grants access to specific applications rather than broad network access. It limits lateral movement.
Secure External Cloud Integration
Q46. A webhook endpoint should be protected using:
- Signature verification and replay protection
- Anonymous unrestricted access
- No logging
- Plain HTTP only
Answer: A) Signature verification and replay protection -> Explanation: Webhook endpoints should be protected using signature verification, timestamp checks, and replay protection to prevent attacks.
Q47. Which item is most suitable for protecting secrets used in external integrations?
- Plain text file
- Source code comments
- Managed secrets vault
- Public chat message
Answer: C) Managed secrets vault -> Explanation: A managed secrets vault is most suitable for protecting secrets. It stores and rotates credentials securely.
Q48. Which integration type connects an enterprise application to an external SaaS service?
- SaaS integration
- Partner API
- Cross-cloud integration
- Webhook integration
Answer: A) SaaS integration -> Explanation: SaaS integration connects an enterprise application to an external SaaS service. Examples: CRM, HRMS, email, learning management system.
Q49. What is the risk of excessive third-party access?
- Provider receives more data or permissions than required
- Provider has no access
- Data is encrypted
- Logs are disabled
Answer: A) Provider receives more data or permissions than required -> Explanation: Excessive third-party access means the provider receives more data or permissions than required. Control: Use minimal scopes and contractual data limits.
Q50. Which is a control for provider compromise?
- Monitor integration behaviour and revoke tokens quickly
- Ignore provider activity
- Share more data
- Disable logging
Answer: A) Monitor integration behaviour and revoke tokens quickly -> Explanation: Provider compromise occurs when an external system is attacked and used to access enterprise data. Control: Monitor integration behaviour and revoke tokens quickly.
SECTION B: THEORY QUESTIONS (20)
Q1. Define cloud security design pattern. Explain why design patterns are important in cloud architecture.
Answer:
A cloud security design pattern is a reusable architectural solution for common security problems that occur in cloud and hybrid cloud environments. It helps architects and engineers design systems that are secure, scalable, auditable, and aligned with business requirements.
Why Design Patterns Are Important:
| Reason | Explanation | Example |
|---|---|---|
| Consistency | Apply the same security logic across multiple applications | All APIs use the same gateway, logging, and authorization checks |
| Scalability | Security controls scale with dynamic cloud resources | New instances receive baseline firewall and IAM policies automatically |
| Auditability | Patterns define expected controls, making audits easier | A storage access pattern includes encryption, logging, and role review |
| Risk Reduction | Known weak points are addressed before deployment | External integrations use token rotation and restricted scopes |
| Communication | Teams use a common vocabulary | “Use secure interface pattern” instead of listing every API control |
Best Practice: Design patterns should be supported by policy as code, infrastructure as code, automated testing, and continuous monitoring.
Q2. Explain the structure of a cloud security design pattern.
Answer:
A good cloud security design pattern explains the problem, when the pattern is suitable, what controls are required, what risks remain, and how implementation can be verified.
| Pattern Element | Purpose | Security Example |
|---|---|---|
| Problem | States the recurring issue | Users need secure access to cloud APIs from different locations |
| Context | Explains where the problem appears | Hybrid cloud, mobile users, SaaS integration |
| Forces | Lists competing requirements | Security, performance, cost, latency, compliance |
| Solution | Describes architecture and control flow | API gateway, identity provider, MFA, WAF, centralized logs |
| Controls | Lists required security mechanisms | TLS, IAM policy, logging, rate limiting, secrets management |
| Benefits | Explains positive outcomes | Reduced attack surface, better visibility, easier governance |
| Risks | Mentions limitations and misuse cases | Misconfigured policies, stale tokens, poor monitoring |
| Verification | Defines how to test the pattern | Access tests, penetration test, log review, policy simulation |
Q3. Explain the cloud bursting pattern with a suitable example.
Answer:
Cloud bursting is a hybrid cloud design pattern in which an application normally runs in a private cloud or on-premise data centre, but temporarily expands into a public cloud when demand increases.
Example: A university admission portal may run on its private servers during normal days. During admission result days, traffic may increase suddenly. Instead of buying permanent hardware for a short peak period, the system can burst into a public cloud and run additional application instances there.
Architecture Components:
- Private environment (primary data centre)
- Public cloud environment (temporary capacity)
- Secure connectivity (VPN, private link)
- Traffic management (load balancer, DNS)
- Identity federation
- Data synchronization
- Centralized monitoring
- Automation templates
Workflow:
- Monitor load
- Trigger automation
- Apply security baseline
- Route traffic
- Synchronize data
- Monitor both environments
- Decommission resources
Q4. What is geo-tagging? How does it support data residency and compliance?
Answer:
Geo-tagging is the process of adding geographic or location-based metadata to cloud data, users, devices, workloads, logs, or resources.
Support for Data Residency:
- Tags like
country=India, region=ap-southensure data remains within approved legal jurisdictions - Policy engines block movement of data to unapproved cloud regions
- Example: Customer data stored only in Indian cloud regions
Support for Compliance:
- Supports audits by proving resource and data location
- Demonstrates that regulated records never left approved jurisdictions
- Tracks backup and replica locations for disaster recovery
- Logs every allowed or denied movement of sensitive data
Use Cases:
- Data residency
- Access control (block admin login from unexpected countries)
- Disaster recovery
- Incident response
- Cost and performance
- Legal compliance
Risks and Controls:
| Risk | Control |
|---|---|
| Incorrect tags | Use automated tagging and mandatory tag policies |
| Location spoofing | Combine geo-location with device posture and behaviour analytics |
| Privacy risk | Minimize location detail and protect logs |
| Tag bypass | Block deployment when mandatory tags are missing |
Q5. List and explain any five controls used to secure cloud interfaces.
Answer:
Cloud interfaces are entry points used to access cloud resources (APIs, consoles, CLIs, SDKs, endpoints).
Five Security Controls:
- Strong Authentication:
- Use MFA, SSO, and conditional access
- Verify identity before request processing
- Example: JWT validation using identity provider public keys
- Authorization:
- Separate authentication from authorization
- Check whether the caller may access the operation
- Example: Only finance role can call billing API
- API Gateway:
- Controlled entry point between clients and backend services
- Enforces authentication, authorization, rate limiting, TLS termination
- Example: Log request ID, caller, resource, and decision
- Rate Limiting:
- Reduces brute force and denial-of-service risk
- Limits requests per client
- Example: Maximum 100 requests per minute per client
- Input Validation:
- Validates all input, request size, schema, content type
- Blocks malformed or unexpected requests
- Example: Reject request body that does not match schema
Additional Controls: TLS/mTLS, logging, WAF, secrets management, credential rotation.
Q6. Differentiate between RBAC, ABAC, and tag-based access control.
Answer:
| Model | Description | Cloud Example |
|---|---|---|
| RBAC | Access is based on assigned roles | DatabaseAdmin can manage database instances |
| ABAC | Access is based on attributes of user, resource, action, and context | Allow access only if department=user.department and device is compliant |
| Tag-based access | Resource tags are used in policy conditions | Developers can start resources tagged environment=dev |
RBAC (Role-Based Access Control):
- Users are assigned roles
- Permissions are attached to roles
- Simple to manage
- Example: Admin, Developer, Auditor roles
ABAC (Attribute-Based Access Control):
- Access decisions based on attributes
- User attributes (department, role)
- Resource attributes (sensitivity, owner)
- Context attributes (time, location, device)
- More flexible and fine-grained
Tag-Based Access Control:
- Uses resource tags in policy conditions
- Tags like
environment=dev,region=India - Enables dynamic policy enforcement
- Example: Developers can start only
environment=devresources
Combined Approach: Modern cloud access control combines RBAC + ABAC + Tags for fine-grained control.
Q7. Explain the role of API gateway in secure cloud interface design.
Answer:
An API gateway is a controlled entry point between clients and backend cloud services. It reduces the exposure of internal services and enforces security policies.
Gateway Functions:
| Function | Security Benefit | Example |
|---|---|---|
| Authentication | Verifies identity before request processing | JWT validation using identity provider public keys |
| Authorization | Checks whether the caller may access the operation | Only finance role can call billing API |
| Rate limiting | Reduces brute force and denial-of-service risk | Maximum 100 requests per minute per client |
| Input validation | Blocks malformed or unexpected requests | Reject request body that does not match schema |
| TLS/mTLS | Protects data in transit and verifies endpoints | Client certificate required for partner API |
| Logging | Creates evidence for monitoring and investigation | Log request ID, caller, resource, and decision |
| Transformation | Removes unnecessary exposure of backend structure | Map public API route to internal service route |
Benefits:
- Centralized security enforcement
- Reduced attack surface
- Consistent policy application
- Better monitoring and logging
- Simplified client integration
Q8. What are the security risks of cloud bursting? Suggest suitable controls.
Answer:
Security Risks:
| Risk | Explanation |
|---|---|
| Policy inconsistency | Burst resources may not receive the same security policies |
| Data residency violation | Data may move to unauthorized regions |
| Weak credentials | Temporary resources may use weak or default credentials |
| Exposed ports | Manual configuration may expose unnecessary ports |
| Unapproved data transfers | Sensitive data may be moved without approval |
| Residual risk | Temporary resources may not be properly decommissioned |
Suitable Controls:
| Control Area | Recommended Control |
|---|---|
| Connectivity | Use encrypted tunnels, private connectivity, IPsec VPN |
| Identity | Use federated identity and short-lived credentials |
| Network | Use segmented subnets, security groups, firewalls |
| Data | Classify data before bursting and encrypt replication |
| Configuration | Use hardened images and infrastructure as code |
| Monitoring | Send logs from both environments to a central SIEM |
| Decommissioning | Destroy temporary resources, revoke tokens, wipe storage |
Q9. Explain how secure on-premise internet access protects users and data.
Answer:
Secure on-premise internet access is the design pattern used to protect users, devices, and applications inside an organization when they access the internet, cloud services, or SaaS applications.
Protection Mechanisms:
| Component | Purpose | Security Function |
|---|---|---|
| Firewall | Controls network traffic | Block unauthorized ports, protocols, destinations |
| Proxy / SWG | Inspects web traffic | URL filtering, malware detection, TLS inspection |
| DNS Security | Blocks malicious domains | Prevent command-and-control access |
| CASB | Monitors cloud app usage | Detect shadow IT, enforce SaaS DLP |
| DLP | Prevents data leakage | Block confidential files to unapproved services |
| IDS/IPS | Detects suspicious traffic | Identify exploitation attempts |
| SIEM | Correlates security logs | Alert on abnormal activity |
| ZTNA | Grants app-specific access | Replace broad VPN with application-level access |
Secure Access Flow:
- User connects to enterprise network
- Identity and device posture verified
- DNS checked against threat intelligence
- Traffic passes through secure gateway
- Gateway applies URL filtering, malware inspection, DLP
- Approved traffic forwarded
- Logs sent to monitoring systems
Benefits:
- Malware protection
- Data loss prevention
- User accountability
- Cloud application control
- Policy enforcement
- Remote and branch support
Q10. What is a CASB? Explain its role in cloud application security.
Answer:
CASB (Cloud Access Security Broker) is a security control point that monitors and governs access to cloud applications. It sits between users and cloud services to enforce security policies.
Role in Cloud Application Security:
| Function | Description | Example |
|---|---|---|
| Visibility | Discovers cloud apps in use | Identify sanctioned and unsanctioned SaaS |
| Shadow IT Detection | Detects unauthorized cloud usage | Alert on personal Dropbox usage |
| Data Loss Prevention | Prevents sensitive data leakage | Block upload of customer records to personal storage |
| Compliance | Enforces regulatory requirements | Ensure GDPR-compliant data handling |
| Threat Protection | Detects malicious cloud activity | Block compromised accounts |
| Access Control | Enforces authentication and authorization | Require MFA for cloud app access |
| Encryption | Protects data in cloud apps | Encrypt sensitive files |
Benefits:
- Centralized cloud app governance
- Visibility into cloud usage
- Data protection
- Compliance enforcement
- Threat detection
- Consistent policy application
Q11. Explain webhook security controls in external cloud integration.
Answer:
Webhooks are common in cloud integrations. They allow an external system to send event notifications to an enterprise endpoint. Since webhooks are exposed to external sources, they must be protected carefully.
Webhook Security Checklist:
- Accept requests only over HTTPS
- Verify provider signature using shared secret or public key
- Check timestamp to prevent replay attacks
- Validate request schema and event type
- Process webhook asynchronously through a queue
- Return minimal response information
- Log request ID, provider ID, event type, and decision
Webhook Attacks and Prevention:
| Attack | Prevention |
|---|---|
| Forged requests | Signature verification |
| Replay attacks | Timestamp validation |
| Injection | Schema validation |
| Denial of service | Rate limiting, queue processing |
| Information disclosure | Minimal response |
Best Practices:
- Use HTTPS only
- Verify signatures
- Validate timestamps
- Process asynchronously
- Log all requests
- Monitor for anomalies
Q12. Explain the need for secure on-premise internet access.
Answer:
Even when workloads move to the cloud, many users still connect from offices, campuses, laboratories, or branch networks. Secure on-premise internet access protects these users.
Needs:
| Need | Explanation | Example |
|---|---|---|
| Malware protection | Internet downloads and malicious links can infect devices | Block known malicious domains and scan files |
| Data loss prevention | Sensitive data may be uploaded to unauthorized services | Detect and block customer records sent to personal storage |
| User accountability | Organizations need to know who accessed which site or service | Log user, device, URL, time, and decision |
| Cloud application control | Employees may use unsanctioned SaaS tools | Monitor and control shadow IT |
| Policy enforcement | Different users need different access levels | Allow research sites for students but block risky downloads |
| Remote and branch support | Users may work from multiple locations | Use cloud-delivered secure web gateway or ZTNA |
Architecture Components:
- Firewall
- Proxy / Secure Web Gateway
- DNS Security
- CASB
- DLP
- IDS/IPS
- SIEM
- ZTNA
Q13. Explain the difference between full tunnel and split tunnel.
Answer:
| Approach | Description | Advantages | Security Concern |
|---|---|---|---|
| Full tunnel | All user traffic is routed through enterprise security controls | Maximum visibility and policy control | May increase latency and gateway load |
| Split tunnel | Only selected traffic goes through enterprise controls; other internet traffic exits locally | Better performance and reduced bandwidth cost | Uninspected traffic may increase risk |
Full Tunnel:
- All traffic goes through enterprise security
- Maximum visibility
- Higher latency
- Higher gateway load
Split Tunnel:
- Only selected traffic goes through enterprise
- Better performance
- Reduced bandwidth cost
- Some traffic uninspected
Cloud-Delivered Gateway:
- Traffic inspected by security service close to user
- Good for remote users and branches
- Requires reliable identity and policy integration
Zero-Trust Access:
- Access granted to specific applications
- Limits lateral movement
- Requires mature identity and device posture controls
Best Practice: Secure internet access should not depend only on network location. It should combine identity, device health, application sensitivity, data classification, and behaviour monitoring.
Q14. Explain the cloud bursting architecture in detail.
Answer:
A secure cloud bursting architecture contains:
Components:
- Private environment — Primary data centre where normal workload runs
- Public cloud environment — Temporary additional capacity
- Secure connectivity — VPN, private link, dedicated connection, encrypted tunnel
- Traffic management — Load balancer, DNS routing, global traffic manager
- Identity federation — Consistent authentication across environments
- Data synchronization — Replication with encryption and integrity checks
- Centralized monitoring — Logging and alerting for both components
- Automation templates — For creating and deleting burst resources securely
Security Controls:
| Control Area | Recommended Control | Purpose |
|---|---|---|
| Connectivity | Encrypted tunnels, private connectivity | Protect traffic |
| Identity | Federated identity, short-lived credentials | Avoid unmanaged accounts |
| Network | Segmented subnets, security groups | Limit traffic exposure |
| Data | Classify data, encrypt replication | Prevent unauthorized movement |
| Configuration | Hardened images, infrastructure as code | Avoid manual errors |
| Monitoring | Central SIEM | Detect abnormal activity |
| Decommissioning | Destroy resources, revoke tokens | Reduce residual risk |
Workflow:
- Monitor load
- Trigger automation
- Apply security baseline
- Route traffic
- Synchronize data
- Monitor both environments
- Decommission resources
Q15. Explain secure external cloud integration.
Answer:
Secure external cloud integration is a design pattern for safely connecting an organization’s cloud environment with external systems such as SaaS platforms, partner APIs, payment gateways, and other cloud providers.
Types of Integration:
| Integration Type | Description | Example |
|---|---|---|
| SaaS integration | Enterprise app connects to SaaS | CRM, HRMS, email |
| Partner API | Partner exchanges data | Payment gateway |
| Cross-cloud integration | One cloud communicates with another | Cloud A reads Cloud B |
| Identity federation | External IdP authenticates users | B2B guest users |
| Webhook integration | External service sends callback | Payment notification |
| Data pipeline | Data moved to external processing | Cloud data warehouse |
| Marketplace service | Third-party product deployed | Security scanner |
Security Design Principles:
- Approve through formal risk process
- Use standard protocols (OAuth 2.0, OIDC, SAML, TLS, mTLS)
- Use least-privilege scopes
- Never share root credentials
- Store secrets in managed vault
- Validate webhook signatures
- Encrypt data in transit and at rest
- Log all integration actions
- Define incident response procedures
- Review third-party security posture
Integration Security Layer:
- API gateway
- Token broker
- Message queue
- Schema validator
- Secrets vault
- Data filter
- Audit pipeline
Q16. Explain the role of API gateway in secure cloud interface design.
Answer:
An API gateway is a controlled entry point between clients and backend cloud services. It reduces the exposure of internal services and enforces security policies.
Gateway Functions:
| Function | Security Benefit | Example |
|---|---|---|
| Authentication | Verifies identity | JWT validation |
| Authorization | Checks permissions | Role-based access |
| Rate limiting | Reduces brute force | 100 requests/minute |
| Input validation | Blocks malformed requests | Schema validation |
| TLS/mTLS | Protects data in transit | Client certificate |
| Logging | Creates evidence | Request ID logging |
| Transformation | Hides backend structure | Route mapping |
Benefits:
- Centralized security enforcement
- Reduced attack surface
- Consistent policy application
- Better monitoring
- Simplified client integration
Common Threats Mitigated:
- Broken object authorization
- Excessive permissions
- Credential exposure
- Injection attacks
- API abuse
- Weak TLS
- Poor logging
Q17. Explain the difference between CREATE and MERGE commands in Cypher with suitable examples.
Answer:
Note: This question relates to graph databases (Neo4j). In Cypher:
CREATE:
- Always creates new nodes or relationships
- Does not check if data exists
- Can create duplicates
- Example:
CREATE (p:Person {name: 'Alice', age: 25})
RETURN p;Run twice → Two separate nodes (duplicates)
MERGE:
- Creates only if not exists
- If exists, matches existing
- Prevents duplicates
- Example:
MERGE (p:Person {name: 'Alice', age: 25})
RETURN p;Run twice → Only one node created
| Aspect | CREATE | MERGE |
|---|---|---|
| Behaviour | Always creates | Creates only if not exists |
| Duplicate Data | Can create duplicates | Prevents duplicates |
| Use Case | Always create new | Ensure uniqueness |
| Repeated Execution | Multiple identical nodes | Single node |
Key Takeaway: Use CREATE when you want to always create. Use MERGE when you want to create only if it doesn’t exist.
Q18. Explain the Cache-Aside (Lazy Loading) strategy.
Answer:
Cache-Aside Strategy (Lazy Loading): The application is responsible for loading data into the cache. Data is fetched from the cache first; if not found, it is loaded from the database and then stored in the cache for future requests.
How It Works:
- Application checks the cache for data
- If found (cache hit), return directly from cache
- If not found (cache miss), fetch from database
- Store in cache (with TTL) and return to client
Read Flow (Cache Miss):
Client → Application → Redis Cache → (not found) → Database
↓
Store in cache (with TTL)
↓
Return data to clientRead Flow (Cache Hit):
Client → Application → Redis Cache → (found) → Return data (fast response)Write Flow:
Application → Update database → Invalidate/delete cache entryExample — E-commerce Product Details: When a user views a product (e.g., product ID 101), the application first checks Redis. If not found, it fetches from the database, stores in Redis (e.g., for 5 minutes), and returns it.
Benefits:
- Reduces database load
- Improves application performance
- Simple to implement
- Works well for read-heavy applications
- Gives control to the application
Considerations:
- First request is slower (cache miss)
- Need to handle cache invalidation
- Possibility of stale data
- Choose appropriate TTL
Q19. Explain the key terms in Apache Cassandra.
Answer:
Apache Cassandra is a distributed wide-column NoSQL database.
Key Terms:
| Term | Definition |
|---|---|
| Node | A single instance of Cassandra running on a machine. Each node stores a portion of the data. Nodes are equal (no master/slave). |
| Cluster | A group of nodes that work together to store and manage data. All nodes are peer-to-peer. Provides high availability and scalability. |
| Keyspace | A top-level container (similar to a database). Defines replication settings and contains one or more tables. |
| Partition | A subset of data identified by a partition key. Rows with the same partition key are stored together. |
| Replication Factor | The number of copies of each partition stored across different nodes. RF=3 means 3 copies of each partition. |
Data Model Hierarchy:
Cluster → Keyspace → TableCQL Commands:
-- Create keyspace
CREATE KEYSPACE university
WITH replication = {
'class': 'SimpleStrategy',
'replication_factor': 3
};
-- Use keyspace
USE university;
-- Create table
CREATE TABLE students (
student_id int,
name text,
department text,
age int,
PRIMARY KEY (student_id)
);Benefits:
- High availability
- Fault tolerance
- Horizontal scalability
- No single point of failure
Q20. Explain the Property Graph Model.
Answer:
The property graph model is a graph data model in which data is represented using nodes and relationships, and both nodes and relationships can have properties in the form of key-value pairs.
Components:
| Component | Description | Example |
|---|---|---|
| Nodes | Represent entities or objects | Person, Product, Company |
| Labels | Identify the type or category of a node | :Person, :Course |
| Relationship Types | Describe the nature of connection | ENROLLED_IN, FRIEND_OF |
| Properties | Key-value pairs storing information | {name: "Alice", age: 25} |
Example — University Graph:
:Student (Alice) :Course (NoSQL)
{id: 1, name: "Alice", age: 20} {id: 101, name: "NoSQL", credits: 4}
│ │
│ ENROLLED_IN (year: 2026) │ TAUGHT_BY (semester: "Fall 2026")
└─────────────────────────────────────┘
│ │
│ WORKS_AT (since: 2023) │
↓ ↓
:Company (ABC Corp) :Teacher (Dr. Kumar)
{id: 201, name: "ABC Corp", {id: 301, name: "Dr. Kumar",
industry: "IT"} department: "CSE"}Legend:
- ○ = Node
- → = Relationship (with direction)
- {…} = Properties
:Label= Node label
Key Takeaway: Labels tell us what a node is, while relationship types tell us how two nodes are connected.
Cypher Example:
CREATE (a:Student {id: 1, name: 'Alice', age: 20})
CREATE (c:Course {id: 101, name: 'NoSQL', credits: 4})
CREATE (a)-[:ENROLLED_IN {year: 2026}]->(c)SECTION C: ANALYTICAL QUESTIONS (10)
Q1. Analyze the following scenario and recommend appropriate cloud security design patterns.
Scenario: A university hosts its student portal on private infrastructure. During admission and examination result days, the portal receives heavy traffic. The university also uses a third-party payment gateway, a cloud-based email service, and a student document storage service. Students and staff access the portal from campus, home, and mobile networks.
Answer:
Recommended Design Patterns:
| Pattern | Reason |
|---|---|
| Cloud Bursting | Handle peak traffic during admission/result days without permanent hardware |
| Secure Cloud Interfaces | Protect APIs and portals used by students, staff, and payment gateway |
| Cloud Resource Access Control | Define access rules for students, faculty, administrators, and service accounts |
| Geo-Tagging | Ensure student records, payment logs, and backups comply with data residency |
| Secure On-Premise Internet Access | Protect users accessing the portal from campus and home |
| Secure External Cloud Integration | Securely integrate payment gateway, email service, and storage service |
Cloud Bursting Architecture:
Private Infrastructure → Secure Connectivity → Public Cloud Burst
↓ ↓ ↓
Load Balancer ←────────── VPN/Tunnel ──────────→ Load Balancer
↓ ↓
Private Servers Cloud InstancesAccess Control Rules:
| Role | Access |
|---|---|
| Students | View results, pay fees, access documents |
| Faculty | Manage courses, view student data |
| Administrators | Full access (with MFA) |
| Service accounts | Payment gateway, email, storage (scoped) |
Geo-Tagging Policy:
| Object | Geo-Tag |
|---|---|
| Student records | country=India, residency=India |
| Payment logs | country=India, class=PII |
| Backups | backup_location=approved_region |
External Integration Checklist:
- Use OAuth 2.0 for payment gateway
- Validate webhook signatures
- Store secrets in vault
- Encrypt data in transit and at rest
- Log all integration actions
- Review third-party security posture
Q2. Analyze the security risks of cloud bursting and propose controls.
Answer:
Scenario: An e-commerce company runs most workloads in a private cloud but experiences high traffic during festival sales. They want to use cloud bursting.
Security Risks:
| Risk | Explanation |
|---|---|
| Policy inconsistency | Burst resources may not receive same security policies |
| Data residency violation | Data may move to unauthorized regions |
| Weak credentials | Temporary resources may use weak credentials |
| Exposed ports | Manual configuration may expose ports |
| Unapproved data transfers | Sensitive data may be moved without approval |
| Residual risk | Resources may not be decommissioned |
Proposed Controls:
| Control Area | Control |
|---|---|
| Connectivity | Use encrypted tunnels, private connectivity, IPsec VPN |
| Identity | Use federated identity and short-lived credentials |
| Network | Use segmented subnets, security groups, firewalls |
| Data | Classify data before bursting, encrypt replication |
| Configuration | Use hardened images and infrastructure as code |
| Monitoring | Send logs from both environments to central SIEM |
| Decommissioning | Destroy resources, revoke tokens, wipe storage |
Workflow:
- Monitor load during festival sales
- Trigger automation when threshold reached
- Apply security baseline (IAM, network, encryption, logging)
- Route traffic to cloud instances
- Synchronize only approved data
- Monitor both environments
- Decommission after peak
Benefits:
- Handle peak traffic without permanent hardware
- Cost optimization
- Business continuity
- Geographic reach
Q3. Analyze how geo-tagging, encryption, logging, and access control can be used to protect patient data in a hospital cloud.
Answer:
Scenario: A hospital stores patient data in the cloud and must ensure records do not leave approved regions.
Solution Using Geo-Tagging, Encryption, Logging, and Access Control:
1. Geo-Tagging:
- Tag patient records with
country=India, region=ap-south - Tag backups with
backup_location=approved_region - Policy engine blocks movement to unapproved regions
- Audit logs prove records never left approved jurisdictions
2. Encryption:
- Encrypt data at rest (AES-256)
- Encrypt data in transit (TLS 1.3)
- Encrypt replication traffic
- Use customer-managed keys (CMK)
- Key rotation policy
3. Logging:
- Log every access to patient records
- Log every movement of data
- Log every denied request
- Send logs to central SIEM
- Preserve audit trails for compliance
4. Access Control:
- Use RBAC: Doctors, Nurses, Admins, Auditors
- Use ABAC: Allow access only if department=user.department
- Use tag-based access:
environment=production - Apply least privilege
- Use just-in-time access for admins
- Regular access reviews
Combined Protection:
Patient Data → Geo-Tag → Policy Engine → Allow/Deny
↓
Encryption → TLS/AES
↓
Logging → SIEM
↓
Access Control → RBAC/ABACBenefits:
- Data residency compliance
- Data protection
- Auditability
- Access control
- Incident response
Q4. Analyze the security controls needed for a startup exposing APIs to mobile apps and partner vendors.
Answer:
Scenario: A startup exposes APIs to mobile apps and partner vendors.
Secure Cloud Interface Pattern:
Mobile Apps → API Gateway → AuthN/AuthZ → Cloud Services
Partner Vendors → API Gateway → AuthN/AuthZ → Cloud ServicesControls:
| Control | Implementation |
|---|---|
| Authentication | OAuth 2.0 / OIDC for mobile apps; mTLS for partners |
| Authorization | Role-based scopes; partner-specific permissions |
| Rate Limiting | 100 requests/minute per client; burst protection |
| Input Validation | Schema validation; reject malformed requests |
| TLS/mTLS | TLS 1.3 for mobile; mTLS for partners |
| Logging | Log request ID, caller, resource, decision |
| WAF | Block injection, XSS, bot attacks |
| Secrets Management | Vault for API keys, certificates |
| Monitoring | SIEM alerts on anomalies |
API Gateway Functions:
- Authentication (JWT validation)
- Authorization (role checks)
- Rate limiting (per client)
- Input validation (schema)
- TLS termination
- Logging (audit)
- Transformation (hide backend)
Partner Onboarding:
- Risk assessment
- Data classification
- Scope definition (least privilege)
- Contract with data limits
- mTLS certificate issuance
- Monitoring setup
- Regular review
Threats Mitigated:
- Broken object authorization
- Excessive permissions
- Credential exposure
- Injection attacks
- API abuse
- Weak TLS
- Poor logging
Q5. Analyze the secure on-premise and remote internet access pattern for employees accessing SaaS applications from campus and home.
Answer:
Scenario: Employees access SaaS applications from campus and home.
Recommended Pattern:
On-prem users → SWG/Proxy → Firewall/IDS/DLP → Internet + SaaS
↓ ↓ ↓ ↓
DNS Security URL Filtering Malware Insp. CASB Rules
TLS Inspection User Logs Zero TrustComponents:
| Component | Purpose | Security Function |
|---|---|---|
| Firewall | Control traffic | Block unauthorized ports |
| SWG/Proxy | Inspect web traffic | URL filtering, malware detection |
| DNS Security | Block malicious domains | Prevent C2 access |
| CASB | Monitor cloud apps | Detect shadow IT, enforce DLP |
| DLP | Prevent data leakage | Block confidential uploads |
| IDS/IPS | Detect threats | Identify exploitation |
| SIEM | Correlate logs | Alert on anomalies |
| ZTNA | App-specific access | Replace broad VPN |
Access Flow:
- User connects (campus or home)
- Identity and device posture verified
- DNS checked against threat intelligence
- Traffic passes through secure gateway
- Gateway applies URL filtering, malware inspection, DLP
- Approved traffic forwarded
- Logs sent to SIEM
Tunnel Approaches:
| Approach | Use Case |
|---|---|
| Full tunnel | Maximum visibility (campus) |
| Split tunnel | Better performance (home) |
| Cloud-delivered gateway | Remote users, branches |
| Zero-trust access | App-specific access |
Benefits:
- Malware protection
- Data loss prevention
- User accountability
- Cloud application control
- Policy enforcement
- Remote support
Best Practice: Combine identity, device health, application sensitivity, data classification, and behaviour monitoring.
Q6. Analyze the secure integration checklist for a college portal integrating with an external payment gateway using webhooks.
Answer:
Scenario: A college portal integrates with an external payment gateway using webhooks.
Secure Integration Checklist:
1. Authentication & Authorization:
- Use OAuth 2.0 / OIDC for API access
- Use least-privilege scopes
- Never share root credentials
- Store API keys in managed vault
2. Webhook Security:
- Accept requests only over HTTPS
- Verify provider signature (shared secret or public key)
- Check timestamp to prevent replay attacks
- Validate request schema and event type
- Process webhook asynchronously through a queue
- Return minimal response information
- Log request ID, provider ID, event type, decision
3. Data Protection:
- Encrypt data in transit (TLS 1.3)
- Encrypt data at rest (AES-256)
- Minimize data shared (only order ID, amount)
- Do not send full customer profile
4. Secrets Management:
- Store secrets in managed vault
- Rotate keys regularly
- Use automated scanning for leaks
- Never store secrets in code or logs
5. Monitoring & Logging:
- Log all integration actions
- Monitor for abnormal usage
- Alert on suspicious activity
- Send logs to SIEM
6. Third-Party Risk:
- Review payment gateway security posture
- Check compliance reports (PCI DSS)
- Define incident response procedures
- Define exit/offboarding process
7. Integration Security Layer:
College Portal → API Gateway → Token Broker → Payment Gateway
↓
Secrets Vault
↓
Audit PipelineWebhook Attack Prevention:
| Attack | Prevention |
|---|---|
| Forged requests | Signature verification |
| Replay attacks | Timestamp validation |
| Injection | Schema validation |
| DoS | Rate limiting, queue |
| Info disclosure | Minimal response |
Q7. Analyze the access control requirements for a developer needing access to a development database but not production customer records.
Answer:
Scenario: A developer needs access to a development database but must not access production customer records.
Access Control Solution:
Access Rule:
Subject: user in group = Developers
Action: read/write database records
Resource condition: tag environment = development
Network condition: access from corporate VPN or trusted deviceCombined Approach:
| Model | Implementation |
|---|---|
| RBAC | Assign role Developer |
| ABAC | Allow if department=user.department and device compliant |
| Tag-based | Resource tag environment=development |
| Just-in-time | Temporary access for specific tasks |
| Policy-based | Central policy denies production access |
Policy Decision:
IF user.role = Developer
AND resource.tag.environment = development
AND network = corporate VPN
AND device = compliant
THEN allow
ELSE denyComponents:
| Component | Role |
|---|---|
| Identity Provider | Authenticate developer |
| Policy Decision Point | Evaluate request |
| Policy Enforcement Point | Enforce decision |
| Policy Information Point | Provide context (device, location, tags) |
| Audit System | Record decisions |
| Secrets Manager | Store credentials |
Mistakes to Avoid:
- Using root account
- Permanent admin roles
- Wildcard permissions
- Direct user permissions
- Unrotated access keys
- No access review
- No deny guardrails
Benefits:
- Least privilege
- Separation of duties
- Auditability
- Risk reduction
- Compliance
Q8. Analyze the security architecture for a hybrid college portal using cloud bursting, geo-tagging, and external integration.
Answer:
Scenario: A college hosts its student portal on private infrastructure. During admission and result days, traffic spikes. The college uses a payment gateway, cloud email, and document storage.
Security Architecture:
┌─────────────────────────────────────────────────────────────┐
│ COLLEGE PORTAL │
├─────────────────────────────────────────────────────────────┤
│ Private Infrastructure │ Public Cloud Burst │
│ ┌─────────────┐ │ ┌─────────────┐ │
│ │ Web Servers │←── VPN/Tunnel ──│─→│ Cloud │ │
│ │ Database │ │ │ Instances │ │
│ └─────────────┘ │ └─────────────┘ │
│ ↓ │ ↓ │
│ ┌─────────────┐ │ ┌─────────────┐ │
│ │ Load │←───────────────│─→│ Load │ │
│ │ Balancer │ │ │ Balancer │ │
│ └─────────────┘ │ └─────────────┘ │
├─────────────────────────────────────────────────────────────┤
│ Identity Federation (SSO, MFA) │
├─────────────────────────────────────────────────────────────┤
│ Geo-Tagging Policy Engine │
│ - Student records: country=India, residency=India │
│ - Payment logs: class=PII, country=India │
│ - Backups: backup_location=approved_region │
├─────────────────────────────────────────────────────────────┤
│ External Integrations │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Payment │ │ Email │ │ Document │ │
│ │ Gateway │ │ Service │ │ Storage │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
│ ↓ ↓ ↓ │
│ ┌─────────────────────────────────────────────────┐ │
│ │ Integration Security Layer │ │
│ │ API Gateway | Token Broker | Secrets Vault │ │
│ │ Schema Validator | Audit Pipeline │ │
│ └─────────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────────┘Components:
| Component | Purpose |
|---|---|
| Cloud Bursting | Handle peak traffic |
| Geo-Tagging | Data residency compliance |
| Secure Interfaces | Protect APIs and portals |
| Access Control | RBAC/ABAC for users |
| External Integration | Secure payment, email, storage |
Access Control Rules:
| Role | Access |
|---|---|
| Students | View results, pay fees |
| Faculty | Manage courses |
| Admins | Full access (MFA) |
| Services | Scoped access |
Security Controls:
- Cloud bursting: VPN, IAM, data classification, SIEM
- Geo-tagging: Mandatory tags, region restrictions
- Interfaces: API gateway, MFA, OAuth, WAF
- Access control: RBAC, ABAC, least privilege
- Integration: mTLS, scopes, vault, webhook validation
Q9. Analyze the role of CASB in cloud application security for a university.
Answer:
Scenario: A university wants to monitor and govern cloud application usage by students and staff.
CASB (Cloud Access Security Broker) Role:
| Function | Description | Example |
|---|---|---|
| Visibility | Discover cloud apps in use | Identify sanctioned/unsanctioned SaaS |
| Shadow IT Detection | Detect unauthorized cloud usage | Alert on personal Dropbox |
| Data Loss Prevention | Prevent sensitive data leakage | Block student records to personal storage |
| Compliance | Enforce regulatory requirements | GDPR, FERPA compliance |
| Threat Protection | Detect malicious cloud activity | Block compromised accounts |
| Access Control | Enforce authentication | Require MFA for cloud apps |
| Encryption | Protect data in cloud apps | Encrypt sensitive files |
Deployment:
Users → CASB → Cloud Apps (SaaS)
↓
Policy Engine
↓
DLP / Threat Protection
↓
Logging / SIEMBenefits:
- Centralized cloud app governance
- Visibility into cloud usage
- Data protection
- Compliance enforcement
- Threat detection
- Consistent policy application
Use Cases:
- Monitor student email usage
- Block unauthorized file sharing
- Enforce MFA for cloud apps
- Detect compromised accounts
- Prevent data leakage
- Ensure compliance
Integration with Other Controls:
- SWG for web traffic inspection
- DLP for data protection
- SIEM for log correlation
- ZTNA for app-specific access
Q10. Analyze the complete security design for a hospital cloud using all patterns.
Answer:
Scenario: A hospital stores patient data in the cloud and must ensure records do not leave approved regions.
Complete Security Design:
1. Cloud Bursting:
- Private hospital servers for normal load
- Public cloud burst for peak (e.g., pandemic)
- Secure connectivity (VPN)
- Identity federation
- Data classification before bursting
- Central SIEM
2. Geo-Tagging:
- Patient records:
country=India, region=ap-south - Backups:
backup_location=approved_region - Policy engine blocks unapproved regions
- Audit logs prove compliance
3. Secure Cloud Interfaces:
- API gateway for EMR APIs
- MFA for doctors/nurses
- OAuth 2.0 for mobile apps
- Rate limiting
- Input validation
- TLS 1.3
- Logging
4. Cloud Resource Access Control:
- RBAC: Doctors, Nurses, Admins, Auditors
- ABAC:
department=user.department - Tag-based:
environment=production - Least privilege
- Just-in-time for admins
- Access reviews
5. Secure On-Premise Internet Access:
- Firewall
- SWG/Proxy
- DNS Security
- CASB
- DLP
- SIEM
- ZTNA
6. Secure External Cloud Integration:
- Integration security layer
- API gateway
- Token broker
- Secrets vault
- Schema validator
- Audit pipeline
- Webhook validation
Architecture:
┌─────────────────────────────────────────────────────────────┐
│ HOSPITAL CLOUD │
├─────────────────────────────────────────────────────────────┤
│ Private Infrastructure │ Public Cloud Burst │
│ ┌─────────────┐ │ ┌─────────────┐ │
│ │ EMR Servers │←── VPN/Tunnel ──│─→│ Cloud │ │
│ │ Database │ │ │ Instances │ │
│ └─────────────┘ │ └─────────────┘ │
├─────────────────────────────────────────────────────────────┤
│ Identity Federation (SSO, MFA) │
├─────────────────────────────────────────────────────────────┤
│ Geo-Tagging Policy Engine │
│ - Patient records: country=India, residency=India │
│ - Backups: backup_location=approved_region │
├─────────────────────────────────────────────────────────────┤
│ Access Control: RBAC + ABAC + Tags │
├─────────────────────────────────────────────────────────────┤
│ Secure Interfaces: API Gateway, WAF, OAuth │
├─────────────────────────────────────────────────────────────┤
│ External Integrations: Payment, Insurance, Labs │
│ ┌─────────────────────────────────────────────────┐ │
│ │ Integration Security Layer │ │
│ │ API Gateway | Token Broker | Secrets Vault │ │
│ │ Schema Validator | Audit Pipeline │ │
│ └─────────────────────────────────────────────────┘ │
├─────────────────────────────────────────────────────────────┤
│ Secure On-Premise Internet Access │
│ Firewall | SWG | DNS | CASB | DLP | SIEM | ZTNA │
└─────────────────────────────────────────────────────────────┘Compliance:
- HIPAA compliance
- Data residency (India)
- Audit trails
- Access controls
- Encryption
Benefits:
- Data protection
- Regulatory compliance
- High availability
- Scalability
- Security
SUMMARY TABLE
| Section | Count | Topics Covered |
|---|---|---|
| MCQ | 50 | Design patterns, cloud bursting, geo-tagging, secure interfaces, access control, internet access, external integration |
| Theory | 20 | Design pattern definition, structure, cloud bursting, geo-tagging, secure interfaces, RBAC/ABAC, API gateway, risks, CASB, webhooks, internet access, tunnels, architecture, external integration, CREATE/MERGE, Cache-Aside, Cassandra, Property Graph |
| Analytical | 10 | University portal scenario, cloud bursting risks, hospital data protection, startup API security, SaaS access, payment gateway integration, developer access, hybrid college portal, CASB for university, complete hospital design |