Oct 06: Cloud, Network, Architecture (24)

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:07 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards
IaaS vs PaaS vs SaaS
IaaS: virtual infrastructure (VMs, storage). PaaS: platform to build/run apps. SaaS: ready-to-use software.
2
New cards
Shared responsibility model
Provider secures the cloud itself; the customer secures what they put in it. More customer duty with IaaS, least with SaaS.
3
New cards
Cloud deployment models
Public, private, hybrid, community.
4
New cards
Serverless (FaaS)
Run code without managing servers; billed per execution.
5
New cards
Microservices
Application split into small independent services.
6
New cards
Infrastructure as code (IaC)
Define and deploy infrastructure through code for consistency and repeatability.
7
New cards
SDN
Software-defined networking: control plane is separated from the data plane.
8
New cards
Containers vs virtual machines
Containers share the host OS kernel and are lightweight. VMs each include a full OS and are more isolated.
9
New cards
Air gap
Physical isolation from other networks, including the internet.
10
New cards
Zero trust planes
Control plane: policy engine, policy administrator. Data plane: policy enforcement point (PEP) enforces access.
11
New cards
Screened subnet (DMZ)
Buffer zone between internet and internal network for public-facing servers.
12
New cards
Jump server
Hardened host used to administer systems in a separate security zone.
13
New cards
Proxy server
Intermediary for client requests; filters and caches. Reverse proxy sits in front of servers.
14
New cards
Load balancer
Distributes traffic across servers for availability and scale.
15
New cards
IDS vs IPS
IDS detects and alerts. IPS sits inline and can block.
16
New cards
WAF
Web application firewall: filters HTTP/HTTPS traffic to defend against web attacks.
17
New cards
NGFW / UTM
Next-gen firewall: app-aware inspection. UTM: bundles multiple security functions in one device.
18
New cards
Stateless vs stateful firewall
Stateless: checks each packet in isolation. Stateful: tracks connection state.
19
New cards
802.1X
Port-based network access control using authentication (e.g., RADIUS).
20
New cards
IPsec tunnel vs transport mode
Tunnel: encrypts the entire original packet (site-to-site VPN). Transport: encrypts only the payload.
21
New cards
SASE / SD-WAN
SD-WAN: software-defined WAN routing. SASE: converges networking with cloud security services.
22
New cards
Fail-open vs fail-closed
Fail-open: allows traffic on failure (availability). Fail-closed: blocks on failure (security).
23
New cards
Active/active vs active/passive
Active/active: all nodes handle load. Active/passive: standby takes over on failure.
24
New cards
ICS / SCADA / IoT / RTOS
Specialized, often legacy or embedded systems; hard to patch, so isolate and segmen