Cloud Computing Week 6 Assignment Answer
Cloud Computing Week 6 Assignment Answer
Course Link : Click Here
1. An attacker captures a legitimate authentication token from a user session and replays that token later to perform actions as the user. This kind of attack primarily compromises which security property?
A) Confidentiality
B) Integrity
C) Availability
D) Authenticity
Answer : d
2. A well-crafted phishing email (that impersonates a bank and convinces a user to provide credentials) can affect which of the following?
A) Confidentiality
B) Availability
C) Integrity
D) Authenticity
Answer : a
3. Which of the following is a passive attack?
A) Modifying packets in transit to change their payload
B) Injecting forged packets into an existing TCP connection
C) Traffic analysis to infer communication patterns between two hosts
D) Launching a Denial-of-Service (DoS) attack to disrupt service
Answer : c
4. An attacker floods a web application with slow HTTP POSTs that hold connections open and exhaust
the server’s connection pool, causing legitimate clients to experience severe delays. This attack is
best classified as:
A) Disruption
B) Disclosure
C) Usurpation
D) Deception
Answer : a
5. Which activity both attempts to exploit vulnerabilities and demonstrates real-world impact (often
requiring written authorization before it’s performed)?
A) Reconnaissance
B) Vulnerability scanning
C) Penetration testing
D) Post-attack investigation
Answer : c
6. Which of the following mechanisms most directly provides non-repudiation for an online financial
transaction?
A) Using a strong password over HTTPS
B) Encrypting data using a shared symmetric key
C) Logging IP addresses and timestamps in a database
D) Digitally signing the transaction with the sender’s private key
Answer : d
7. Statement I: Authorization is the process of verifying the identity of a user or system.
Statement II: Non-repudiation ensures that a sender cannot later deny having sent a specific message.
Options:
A) I TRUE, II FALSE
B) IFALSE, II TRUE
C) Both TRUE
D) Both FALSE
Answer : b
8. A start-up wants to deploy a custom web application. They want to upload their application code and have the provider manage the underlying OS patches, middleware, and runtime, while still allowing them to configure application settings and scale instances. Which cloud service model best fits?
A) Saas
B) IaaS
C) PaaS
D) DaaS
Answer : c
9. A country’s data protection law requires that all personal data of its citizens must be stored and
processed only within that country’s geographic boundaries, even when using cloud services. This
concern is most closely related to which cloud security risk category?
A) Regulatory Compliance & Audit
B) Data Location
C) Disaster Recovery & Business Continuity
D) Investigative Support
Answer : b
10. Vendor lock-in is most directly associated with which long-term viability challenge?
A) Difficulty in migrating data to another provider
B) Unauthorized data disclosure
C) Increased regulatory audits
D) Privileged user misuse
Answer : a
For other NPTEL Assignment Answer : Click Here