100% CORRECT ANSWERS. r r r
1. The management plane is use to administer a cloud environment and per-
r
.q r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q
form administrative tasks across a variety of systems, but most specifically
.q r r
.q r
.q r
.q .q r r
.q .q r .q r r
.q r
.q .q r
it's used with the hypervisors.
.q r r
.q r
.q r
.q r
.q
What does the management plane typically leverage for this orchestration?
r
.q .q r r
.q r
.q .q r r
.q r
.q r
.q r
.q
A. APIs
B. Scripts
C. TLS
D. XML ANS: ThemanagementplaneusesAPIstoexecuteremotecallsacrossthecloud
r rr
.q .q .q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
environmenttovariousmanagementsystems,especiallyhypervisors.Thisallowsa
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
centralizedadministrativeinterface,oftenawebportal,toorchestrate tasksthrough- out
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
anenterprise.ScriptsmaybeutilizedtoexecuteAPIcalls,buttheyarenotused directly to
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r
interact with systems.XML is used for data encoding and transmission, butnotfor
.q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r .q r r
.q r
.q
executingremotecalls.TLSis usedto encryptcommunicationsandmay be used with
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r .q r
API calls, but it is not the actual process for executing commands.
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
2. When dealing with PII, which category pertains to those requirements that r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r
can carry legal sanctions or penalties for failure to adequately safeguard the
.q r r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q r
.q
data and address compliance requirements?
.q r r
.q r
.q r
.q r
.q
A. Contractual
B. Jurisdictional
C. Regulated
D. Legal ANS: Regulated PII pertains to data that is outlined in law and regulations.
rr r rr
.q .q .q .q .q r
.q .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
Violations of the requirements for the protection of regulated PII can carry legal
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
sanctions or penalties.Contractual PII involves required data protection that is
.q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r
r r
.q .q
,determined by the actual service contract between the cloud provider and cloud
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
customer, rather than outlined by law.Violations of the provisions of contractual PII carry
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r
potential financial or contractual implications, but not legal sanctions. Legal and
.q r .q r .q r .q r .q r .q r .q r .q r .q r r
.q .q r
jurisdictionalaresimilartermstoregulated,butneitheristheofficialtermused.
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
3. Although the united states does not have a single,comprehensive privacy and
r
.q .q r .q r r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q
regulatory framework, a number of specific regulations pertain to types of data
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r r
.q
or populations.
.q r r
.q
Which of the following is NOT a regulatory system from the United States federal
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
government?
.q r
A. HIPAA
B. SOX
r r
.q .q
,C. FISMA
D. PCIDSS ANS:ThePaymentCardIndustryDataSecurityStandard(PCIDSS)pertains
r
.q rrr
.q .q .q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
to organizations that handle credit card transactions and is an industry-regulatory
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
standard, not a governmental one.The Sarbanes-Oxley Act (SOX) was passed
.q r .q r .q r .q r .q r r
.q .q r .q r .q r .q r .q r
in 2002 and pertains to financial records and reporting, as well as transparency
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
requirements for shareholders and other stakeholders.The Health Insurance and
.q r .q r .q r .q r .q r .q r r
.q .q r .q r .q r
PortabilityAct(HIPAA)waspassedin1996andpertainstodataprivacyandsecurity for
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
medicalrecords.FISMA refersto the FederalInformationSecurityManagement Act of
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r r
.q
2002 and pertains to the protection of all US federal government IT systems, with the
r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q .q r .q r
exception of national security systems.
.q r .q r .q r .q r .q r
4. The president of your company has tsked you with implementing cloud r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q r
.q
services as the most efficient way of obtaining a robust disaster recovery
.q r r
.q r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q
configuration for your production services.
.q r .q r .q r r
.q r
.q
Which of the cloud deployment models would you MOST likely be exploring? r
.q .q r r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q
A. Hybrid
B. Private
C. Community
D. Public ANS: A hybrid cloud model spans two more different hosting configurations rr r
.q .q .q .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
.or cloud providers.This would enable an organization to continue using its current
q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r .q r .q r
hosting configuration, while adding additional cloud services to enable disaster
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
recoverycapabilities.Theotherclouddeploymentmodels--public,private,andcom-
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
munity--wouldnotbeapplicableforseekingadisasterrecoveryconfigurationwhere
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
cloud services are to be leveraged for that purpose rather than production service
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
hosting.
.q r
5. If you are running an application that has strict legal requirements that the
r
.q .q r .q r r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q r
.q
data cannot reside on systems that contain other applications or systems,
.q r r
.q r
.q .q r r
.q .q r .q r r
.q r
.q .q r r
.q
which aspect of cloud computing would be prohibitive in this case?
.q r r
.q r
.q r
.q .q r r
.q .q r .q r r
.q .q r .q r
A. Multitenancy
B. Broad network access r
.q r
.q
C. Portability
D. Elasticity ANS: Multitenancy is the aspect of cloud computing that involves .q r rr r.q .q .q r
.q .q r .q r .q r .q r .q r .q r .q r .q r
having multiple customers and applications running within the same system and
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
sharing the same resources. Although considerable mechanisms are in place to
.q r .q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r
ensure isolation and separation, the data and applications are ultimately using shared
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
resources.Broad network access refers to the ability to access cloud services from any
.q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r
location or client.Portability refers to the ability to easily move cloud services
.q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r .q r .q r
r r
.q .q
, between different cloud providers, whereas elasticity refers to the capabilities of a clou .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
environment to add or remove services, as needed, to meet current demand.
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
6. The REST API is a widely used standard for communications of web-based
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q
services between clients and the servers hosting them.
.q r r
.q r
.q .q r .q r .q r .q r r
.q
Which protocol does the REST API depend on? .q r r
.q r
.q r
.q r
.q r
.q r
.q
A. HTTP
B. SSH
C. SAML
D. XML: Representational State Transfer (REST) is a software architectural scheme that r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r
applies the components, connectors, and data conduits for many web applica- tions
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r
used on the Internet.It uses and relies on the HTTP protocol and supports
.q r .q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r .q r .q r
a variety of data formats.Extensible Markup Language (XML) and Security Asser- tion
.q r .q r .q r .q r r
.q .q r .q r .q r .q r .q r .q r .q r
Markup Language (SAML) are both standards for exchanging encoded data between
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
two parties, with XML being for more general use and SAML focused on authentication
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
andauthorizationdata.SecureShellclient(SSH)isasecuremethod for allowing remote
r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r .q r
login to systems over a network.
.q r .q r .q r .q r .q r .q r
7. Which of the following actions will NOT make data part of the create phase of r
.q r
.q r
.q .q r .q r r
.q .q r r
.q r
.q r
.q r
.q .q r r
.q r
.q
the cloud data lifecycle?
.q r .q r .q r .q r
A. Modify data .q r
B. Modify metadata .q r
C. New data .q r
D. Import data:Modifying the metadata does not change the actual data.Although this r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r
initial phase is called "create", it can also refer to modification.In essence, any time
.q r .q r r
.q r
.q .q r .q r .q r r
.q r
.q r
.q .q r r
.q r
.q r
.q .q r
data is considered "new", it is in the create phase.This can come from data that is newly
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r r
.q .q r .q r .q r .q r .q r r
.q r
.q
created, data that is imported into a system and is new to that system, or data that is
r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r .q r .q r
already present and is modified into a new form or value.
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
8. Most APIs will support a variety of different data formats or structures. .q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r .q r .q r
However,the SOAP API will only support which one of the following data formats? r
.q r
.q .q r r
.q r
.q r
.q r
.q r
.q r
.q r
.q .q r r
.q r
.q
A. XML
B. XSLT
C. JSON
D. SAML: The Simple Object Access Protocol (SOAP) protocol only supports the r
.q .q r .q r .q r .q r .q r .q r .q r .q r .q r
Extensible Markup Language (XML) data format.Although the other options are all data
.q r r
.q .q r .q r r
.q r
.q r
.q r
.q .q r r
.q r
.q r
.q .q r
formats or data structures, they are not supported by SOAP
.q r .q r .q r .q r .q r .q r .q r .q r .q r .q r
r r
.q .q