ETExamTower
Q37Securing the Cloud

Which risk arises when an Internet browser is used to access a cloud-based service?

← → navigate · a answer
Community votes
D
57% (4)
C
29% (2)
A
14% (1)
B
0% (0)
Discussion · 18
9
I disagree with protocol vulnerabilities. The answer is about insecure implementation of API https://www.imperva.com/blog/top-10-cloud-security-concerns/
5
Agreed, as stated the user is using a Web browser, so it cannot be API, the correct answer is C
4
API and Internet Browser? Definitely not!
C 4
Selected Answer: C Vulnerabilities within protocol: Cross-site scripting (XSS) vulnerabilities: These allow attackers to inject malicious scripts into web pages viewed by other users.
3
Vulnerabilities within protocols that can expose confidential data. That is C, not D!
3
A - Misconfiguration of Infra, which leads to unauthorized access is CORRECT for me --> it combines the 2 most common security issues of public cloud in one answer (see link below) Question says BROWSER so API is probably not an option (D). Vulnerabilities within protocol (C) - this is not specific to cloud, PROTOCOLS are used everywhere and they are years old, tuned standards with minimum vulnerabilities. Option B - connection stability (?) --> means service availability, which is also a security aspect but it is not such a big issue as option A and networks are reliable today (risk is DoS / DDoS but they are not asking about it). A is correct. https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-security/top-cloud-security-issues-threats-and-concerns/
3
another showcase question for why Cisco exams are utter garbage.
C 3
Selected Answer: C When using an Internet browser to access cloud-based services, the main risk is vulnerabilities in the communication protocols (e.g., HTTP, HTTPS, TLS, or WebSockets). Attackers can use these weaknesses through man-in-the-middle (MITM) attacks, SSL/TLS weaknesses, or browser-based exploits.
2
Answer is D Vulnerabilities in protocols that can expose confidential data
2
That is also my answer. You are responsible for configuring users and authentication / authorization for your Cloud, so if you do that in a dumb way it is insecure. Your AWS instances might be publicly reachable over SSL with a Cisco123 password - what do you think ?
D 2
Selected Answer: D Should be D. A poorly designed or implemented API could let users access confidential data unintentionally, e.g. with a typo in the browser address box. A. Wrong. Misconfigured infra, not specifically vulnerable to browsers B. Wrong. Not that significant, although it is an availability issue from a security perspective, but it also has nothing to do with a browser. C. Wrong, vulnerable within protocol? then which protocol? specific to a browser? then should be http or https, however, that also affects non-cloud-based services as well, right?
D 2
Selected Answer: D insecure API: A malicious user gained access to an organization's database from a cloud-base application programming interface that lacked strong authentication control. (from 350 - 701 practice exam)
A 1
Selected Answer: A VM might be publicly reachable and the WebUI is weakly protected by a default password like Cisco123.
1
I would go with C
1
I think D
1
Correct answer C. I checked with securitytut
D 1
Selected Answer: D I think it is about securing APIs. A web API can still be accessed via a web browser. https://stackoverflow.com/questions/29105007/how-to-make-basic-rest-api-calls-using-a-browser
1
My answer is c