액세스 권한을 부여할 때 적절한 인증 수준을 결정하기 위해 애플리케이션에 정보를 제공하는 것은 무엇입니까?
정답: D
Upon successful user authentication, the identity provider gives information about the user to the relying party that it needs to make authorization decisions for granting access as well as the level of access needed.
CCSP-KR 문제 193
PaaS 솔루션을 사용할 때 고객에게 제공되는 기능은 무엇입니까?
정답: B
According to "The NIST Definition of Cloud Computing," in PaaS, "the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
CCSP-KR 문제 194
조직에서 원하는 클라우드 컴퓨팅의 핵심 기능이 사용 가능한 리소스에 대한 제한이나 우려 없이 확장할 수 있는 능력이라면, 어떤 클라우드 배포 모델을 가장 고려할 것입니까?
정답: A
Public clouds, such as AWS and Azure, are massive systems run by major corporations, and they account for a significant share of Internet traffic and services. They are always expanding, offer enormous resources to customers, and are the least likely to run into resource constraints compared to the other deployment models. Private clouds would likely have the resources available for specific uses and could not be assumed to have a large pool of resources available for expansion. A community cloud would have the same issues as a private cloud, being targeted to similar organizations. A hybrid cloud, because it spans multiple clouds, would not fit the bill either, without the use of individual cloud models.
CCSP-KR 문제 195
비즈니스 연속성과 재해 복구는 어떤 보안 개념에 속합니까?
정답: B
Disaster recovery and business continuity are vital concerns with availability. If data is destroyed or compromised, having regular backup systems in place as well as being able to perform disaster recovery in the event of a major or widespread problem allows operations to continue with an acceptable loss of time and data to management. This also ensures that sensitive data is protected and persisted in the event of the loss or corruption of data systems or physical storage systems.