CompTIA Cloud Essentials+ (CLO-002) flashcards
134 free flashcards. Tap a card to flip it.
Cloud Cost Optimization
Flip cardThe process of managing and reducing cloud spending by optimizing resource usage, selecting appropriate pricing models, and eliminating waste.
- Focuses on aligning costs with business value.
- Strategies include rightsizing, automation, and leveraging discounts.
- Continuous process that requires monitoring and analysis.
Memory trick: Stop the idle, rightsize the load, reserve for sure, but pay for what's showed.
SLA Compliance Assessment
Flip cardThe process of verifying if a cloud provider has met the terms and conditions outlined in a Service Level Agreement (SLA), typically involving uptime and performance metrics.
- Requires calculation of actual metrics
- Compares actuals against agreed-upon thresholds
- Multiple metrics can be part of one SLA
Memory trick: To check an SLA, you must measure each promise (uptime, response) and see if it's broken.
Rapid Elasticity
Flip cardThe ability of cloud resources to be quickly and elastically provisioned or released to scale rapidly outward and inward commensurate with demand.
- Automatic scaling of resources.
- Handles unpredictable demand spikes.
- Minimizes over-provisioning and under-provisioning.
Memory trick: BROAD METERS RAPIDLY POOL SELF-SERVICE.
Platform as a Service (PaaS)
Flip cardA cloud computing service model that provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app.
- Cloud provider manages infrastructure, OS, middleware, and runtime.
- User manages applications and data.
- Ideal for developers who want to focus on coding.
Memory trick: I Play Soccer, so I'm fit for the Cloud.
RPO and RTO
Flip cardRecovery Point Objective (RPO) defines the maximum acceptable amount of data loss. Recovery Time Objective (RTO) defines the maximum acceptable downtime after a disaster.
- RPO is measured in time (e.g., 1 hour of data loss).
- RTO is measured in time (e.g., 4 hours to recover).
- Lower RPO/RTO typically means higher cost and complexity.
Memory trick: RPO is how much you lose, RTO is how long you snooze. Match your backups to what you choose.
Multi-cloud / Portability Strategy
Flip cardAn architectural approach using open standards, containers, and platform-agnostic tools to design applications that can run across multiple cloud providers, reducing vendor lock-in risk.
- Uses containers, open APIs, and infrastructure-as-code
- Avoids proprietary provider-specific services where possible
- Directly mitigates vendor lock-in risk
- May increase complexity but improves negotiating leverage and flexibility
Memory trick: 'Containers unlock the cage' — portable design frees you from one provider.
Resource Tagging
Flip cardApplying metadata (key-value pairs) to cloud resources for identification, organization, and management purposes.
- Used for cost allocation, automation, and access control.
- Enables consistent management across diverse resources.
- Tags can be used in policies, reports, and searches.
Memory trick: Tags for your stuff, roles for your rights, audit for the record, scaling for the lights.
Availability Zone (AZ)
Flip cardA physically distinct, isolated location within a cloud region, designed to be independent of other AZs in terms of power, cooling, and networking, for high availability.
- Provides fault isolation within a region.
- Connected by low-latency links.
- Deploying across multiple AZs enhances application availability.
Memory trick: AZs are the building blocks of regional resilience.
Data Integrity
Flip cardThe assurance that data is accurate, consistent, and complete throughout its entire lifecycle and has not been altered or destroyed in an unauthorized manner.
- Protects against unauthorized modification or deletion.
- Essential for trust, compliance, and accuracy.
- Often implemented through hashing, digital signatures, and access controls.
Memory trick: CIA: Confidentiality is secrecy, Integrity is truth, Availability is always there.
Golden Image
Flip cardA pre-configured, hardened virtual machine image (template) that includes the operating system, required applications, and security configurations, used to provision new instances consistently.
- Ensures consistency and compliance for new deployments.
- Reduces manual configuration and potential for human error.
- Often includes security baselines, agents, and closed ports.
Memory trick: A Golden Image is like a master cookie cutter for VMs, ensuring every new one is perfectly shaped and secured.
Object Storage
Flip cardA cloud storage architecture that manages data as objects, offering high scalability, availability, durability, and features like metadata tagging and encryption, accessible via APIs.
- Highly scalable (virtually unlimited).
- High availability and durability.
- Supports encryption at rest and in transit.
- Accessed via API, enabling concurrent access by multiple services.
Memory trick: Objects for Scale, Blocks for OS, Archives for Cold.
Global Reach and Availability Zones
Flip cardA cloud provider's characteristic referring to its extensive network of data centers distributed across various geographic regions, often subdivided into isolated Availability Zones for high availability and disaster recovery.
- Reduces latency for global users
- Enables compliance with data residency laws
- Provides enhanced resilience and fault tolerance
Memory trick: Cloud providers have global reach, are elastic, offer managed services, and you try to avoid their lock-in.
Shared Responsibility Model (IaaS)
Flip cardA framework outlining the security and compliance responsibilities of both the cloud provider and the customer in a cloud computing environment. In IaaS, the customer has significant responsibility for the operating system and above.
- Provider: 'Security *of* the Cloud' (physical infrastructure, virtualization).
- Customer: 'Security *in* the Cloud' (OS, applications, data, network configuration).
- Responsibility shifts based on service model (IaaS, PaaS, SaaS).
Memory trick: IaaS: They secure the base, you secure your space.
Cloud Monitoring
Flip cardThe process of collecting and analyzing data on the performance, health, and utilization of cloud resources and applications.
- Provides visibility into cloud infrastructure and application behavior.
- Enables proactive identification and resolution of issues.
- Includes metrics, logs, traces, and alerting capabilities.
Memory trick: Provision makes, monitor watches, automate reacts, tag organizes batches.
Shared Responsibility Model
Flip cardA framework defining which security and operational tasks are handled by the cloud provider versus the customer, varying by service model (IaaS, PaaS, SaaS).
- Provider responsibility increases from IaaS to SaaS
- Customer always retains responsibility for data and access management
- Understanding the split prevents security gaps from assumed coverage
Memory trick: The customer always owns the keys to their own data, no matter the model
Hybrid Cloud
Flip cardA cloud computing environment that combines a private cloud with one or more public cloud services, with proprietary software enabling communication between the two distinct environments.
- Combines public and private cloud.
- Allows data and applications to move between environments.
- Ideal for regulatory compliance and workload flexibility.
Memory trick: PPHC: People Play Hard Cloud games.
Operational Expenditure (OpEx)
Flip cardFunds used to run day-to-day business operations, typically expensed in the period in which they are incurred.
- Paid as a recurring cost (e.g., monthly, annually).
- No large upfront investment.
- Common in cloud computing for services like SaaS, IaaS, PaaS.
Memory trick: OpEx is like renting a car, CapEx is buying one.
Total Cost of Ownership (TCO)
Flip cardA comprehensive financial estimate that includes all direct and indirect costs associated with an asset or system over its entire lifecycle.
- Includes hardware, software, services, maintenance, administration, training, energy, downtime.
- Used for comparing different IT solutions (e.g., on-premises vs. cloud).
- Provides a long-term financial perspective.
Memory trick: TCO for the whole cost picture.
Dedicated Cloud Connectivity
Flip cardServices like AWS Direct Connect or Azure ExpressRoute provide a dedicated, private network connection from an on-premises data center to a cloud provider, bypassing the public internet.
- Bypasses the public internet, improving security and performance.
- Offers consistent bandwidth and lower latency.
- Ideal for hybrid cloud environments and large data transfers.
- Requires physical provisioning and typically has recurring costs.
Memory trick: Direct Connect is the private highway to the cloud.
Annualized Loss Expectancy (ALE)
Flip cardA quantitative risk metric calculated as SLE multiplied by ARO, representing the expected yearly financial loss from a given risk.
- SLE = single loss expectancy per incident
- ARO = annualized rate of occurrence (frequency per year)
- ALE = SLE × ARO
- Used to justify cost of controls (should not exceed ALE)
Memory trick: 'ALE Sails Away' — multiply the single loss by how often it hits per year.
NAT Gateway
Flip cardA Network Address Translation service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.
- Enables outbound internet connectivity for private subnets.
- Provides a single public IP address for multiple private instances.
- Crucial for security and controlled internet access.
Memory trick: VPC Network: Gateways for outside, Endpoints for private services.
Technical Feasibility
Flip cardAn assessment of the practical and technical resources required to implement a proposed project or solution, determining if the technology exists and can be integrated.
- Evaluates compatibility with existing systems and infrastructure.
- Assesses availability of required hardware, software, and skills.
- Determines if the project is technically achievable.
Memory trick: TECOS: Tech, Economic, Operational, Schedule.
Refactoring (Re-architecting)
Flip cardA cloud migration strategy that involves making significant modifications to an application's code and architecture to optimize it for cloud-native features and services, improving scalability, performance, and cost-efficiency.
- Involves substantial code changes
- Aims to leverage cloud-native services
- Higher initial effort, but better long-term benefits
- Also known as re-architecting
Memory trick: Refactor: Rebuild for the future cloud.
High Performance IOPS SSD Block Storage
Flip cardA cloud storage type optimized for applications requiring the highest levels of IOPS and lowest latency, often provisioned with dedicated performance characteristics.
- Designed for critical, I/O-intensive databases.
- Guaranteed IOPS and throughput.
- More expensive than other block storage options.
Memory trick: SGH: Some Great Heroes use specialized High IOPS.
Deterrent Control
Flip cardA security control designed to discourage potential attackers or policy violators by warning of consequences, rather than technically preventing or detecting the action.
- Relies on psychological discouragement, not technical blocking
- Examples include warning banners, visible cameras, and legal notices
- One of five main control types alongside preventive, detective, corrective, and compensating
Memory trick: PDCDC: Prevent, Detect, Correct, Deter, Compensate
Virtual Private Cloud (VPC)
Flip cardA logically isolated virtual network within a public cloud provider's infrastructure where users can provision and launch cloud resources.
- Provides network isolation and control.
- Allows defining IP address ranges, subnets, route tables, and network gateways.
- Essential for secure, private cloud deployments and hybrid cloud connectivity.
Memory trick: Cloud networks are like 'private roads' on the internet highway.
Private Cloud
Flip cardA cloud deployment model where computing services are offered either over the Internet or a private internal network and only to select users instead of the general public.
- Dedicated infrastructure for a single organization.
- Offers high levels of security, control, and customization.
- Can be managed by the organization or a third-party.
Memory trick: Private homes are for exclusive control.
Global Load Balancer
Flip cardA network service that distributes incoming application traffic across multiple geographically dispersed servers or data centers to optimize performance, ensure high availability, and facilitate compliance.
- Routes traffic based on user location, server health, and custom policies.
- Essential for multi-region deployments and disaster recovery.
- Can help enforce data residency requirements by directing traffic to specific compliant regions.
Memory trick: Global traffic needs a smart balancer, not just a content network.
Physical Control
Flip cardA security control category that restricts or monitors physical access to facilities, equipment, or infrastructure, such as locks, mantraps, badges, and security guards.
- Protects tangible assets and facility access
- Examples: mantraps, biometric scanners, fences, security guards
- Distinct from administrative (policy) and technical (technology) controls
- Often layered with technical controls for defense in depth
Memory trick: 'Physical = the walls and guards' protecting the building itself.
Compensating Control
Flip cardAn alternative security measure implemented to satisfy the intent of a required control when the original control cannot be applied, commonly required by PCI DSS for legacy systems.
- Must meet the intent and rigor of the original requirement
- Often used when patching or upgrades are not feasible
- Commonly involves layered measures like segmentation, monitoring, and restricted access
Memory trick: PDCDC: Prevent, Detect, Correct, Deter, Compensate
Network Access Control List (NACL)
Flip cardA stateless firewall that controls traffic in and out of one or more subnets within a virtual private cloud (VPC).
- Operates at the subnet level.
- Rules are evaluated in order, from lowest to highest number.
- Stateless: separate rules for inbound and outbound traffic.
- Can be used to block specific IPs or ports.
Memory trick: NACLs are the Neighborhood's Access Control Lists.
Encryption in Transit
Flip cardThe protection of data as it moves across a network between systems, typically implemented using protocols like TLS/SSL to prevent interception.
- Protects against man-in-the-middle attacks
- Distinct from encryption at rest (stored data) and in use (processed data)
- TLS is the most common protocol used for data in transit
Memory trick: In transit = data 'on the highway,' needs a TLS armored truck
Infrastructure as a Service (IaaS)
Flip cardA cloud service model that provides virtualized computing resources over the internet, including virtual machines, networks, and storage. Users manage the operating systems, applications, and data.
- Highest level of control for the user (OS, runtime, apps).
- Cloud provider manages virtualization, servers, storage, networking.
- Suitable for lift-and-shift migrations of legacy applications.
- Requires more management effort from the user than PaaS or SaaS.
Memory trick: IaaS is for Infrastructure, PaaS for Platform, SaaS for Software.
Cloud Readiness Assessment
Flip cardA comprehensive evaluation of an organization's current IT environment, applications, data, security, and operational processes to determine its suitability and preparedness for a cloud migration.
- Identifies gaps and challenges
- Assesses technical and organizational aspects
- Forms the basis for cloud strategy
Memory trick: Before you jump to the cloud, assess if you're ready to fly.
Encryption Key Rotation
Flip cardThe practice of periodically replacing cryptographic keys to limit the amount of data exposed if a key is ever compromised, part of the encryption key lifecycle.
- Reduces the 'blast radius' of a compromised key
- Old keys are retired/destroyed after a grace period
- Part of a broader key management lifecycle including generation, storage, and revocation
Memory trick: GDS-RRD: Generate, Distribute, Store, Rotate, Revoke, Destroy
Rehosting (Lift-and-Shift)
Flip cardA cloud migration strategy that involves moving an application and its data from an on-premises environment to a cloud infrastructure with minimal or no changes.
- Lowest effort for initial migration
- Retains existing architecture and licenses
- May not fully leverage cloud-native features
Memory trick: The 'R's of migration: Rehost is lift-and-shift, Refactor is rebuild, Replatform is tweak, Repurchase is buy new, Retire is delete, Retain is stay put.
Right-Sizing
Flip cardThe process of matching cloud resource capacity (e.g., CPU, memory, storage) to the actual application workload requirements to optimize performance and cost.
- Reduces costs by eliminating over-provisioning.
- Ensures resources are adequate for performance.
- Requires continuous monitoring of resource utilization.
Memory trick: Right-Size to Save Your Cloud Bucks.
Standard Contractual Clauses (SCCs)
Flip cardEU Commission-approved contractual clauses that organizations use to legally transfer personal data to countries outside the EEA that lack an adequacy decision.
- Required when no adequacy decision exists for the destination country
- Impose GDPR-equivalent obligations on the data importer
- One of several approved GDPR transfer mechanisms (also includes Binding Corporate Rules)
- Failure to use a valid mechanism can result in GDPR enforcement action
Memory trick: 'No adequacy? Sign the SCCs' to legally ship data across borders.
Data Classification
Flip cardThe process of categorizing data based on sensitivity level to determine appropriate handling, access, and encryption requirements.
- Common levels: Public, Internal, Confidential, Restricted
- Higher classification requires stricter access controls and encryption
- Helps organizations prioritize protection resources appropriately
Memory trick: PICR: Public is free, Internal is fine, Confidential is careful, Restricted is remote-locked
Automated Provisioning
Flip cardThe process of automatically setting up and configuring IT infrastructure and resources using code or scripts, often including predefined tagging and security policies.
- Ensures consistency and reduces human error.
- Speeds up resource deployment.
- Enforces compliance with organizational policies (e.g., tagging, security).
Memory trick: Provision Automatically, Tag Correctly.
Block Storage
Flip cardA type of data storage that stores data in fixed-size blocks, each with a unique address, allowing for highly efficient and low-latency access.
- Often used for databases and high-performance applications.
- Can be attached directly to virtual machines as a raw disk.
- Provides consistent performance and low latency.
Memory trick: Blocks are like hard drives for databases.
Cloud Global Reach (Regions)
Flip cardThe capability of cloud providers to offer services across geographically dispersed data centers (Regions) to meet requirements for data residency, low latency, and disaster recovery.
- Regions are distinct geographic areas
- Critical for data residency compliance
- Ensures low latency for global users
Memory trick: For global success, think 'R' for Regions for Residency and Reach, not just local 'A' for AZ Availability.
Deprovisioning
Flip cardThe IAM lifecycle stage where user accounts and access rights are disabled or removed once they are no longer needed, such as upon termination or role change.
- Prevents orphaned accounts
- Should occur immediately upon termination
- Part of the identity and access lifecycle
- Reduces attack surface and insider threat risk
Memory trick: 'Deprovision = Door Slammed Shut' the moment someone leaves.
CI/CD Orchestration Engine
Flip cardA software tool that automates the steps of a Continuous Integration/Continuous Delivery pipeline, from code commit to deployment.
- Triggers automated builds, tests, and deployments.
- Manages the workflow of the CI/CD pipeline.
- Examples include Jenkins, GitLab CI, Azure DevOps Pipelines.
Memory trick: Code starts the journey, orchestration drives the car, artifacts are the luggage, monitoring checks afar.
Vendor Lock-In
Flip cardA situation where a customer becomes dependent on a single cloud provider's proprietary technologies, making it difficult or costly to migrate to another provider.
- Caused by proprietary APIs, data formats, or services
- Mitigated by open standards, containers, and multi-cloud strategies
- Increases switching costs and reduces negotiating leverage
Memory trick: Containers = 'portable boxes' that fit on any truck (cloud)
Private Cloud & IaaS
Flip cardA dedicated cloud infrastructure for a single organization (Private Cloud) combined with Infrastructure as a Service, providing virtualized resources and control over OS and network.
- Full isolation and control
- Meets strict data sovereignty
- User manages OS and applications
Memory trick: When 'Strict Control' and 'Isolation' are key, think 'Private' as your own fort and 'IaaS' as having the keys to every room.
On-premises Private Cloud
Flip cardA private cloud deployment where the entire cloud infrastructure, including physical hardware, is owned, operated, and managed by the organization within its own data center.
- Maximum control and security.
- Exclusive access to physical hardware.
- Highest capital expenditure and operational burden for the organization.
Memory trick: ON-PREM HOSTED PRIVATE.
VPC Flow Logs
Flip cardA feature that captures information about the IP traffic going to and from network interfaces in a Virtual Private Cloud (VPC).
- Records source/destination IP, port, protocol, bytes, packets.
- Used for network monitoring, security analysis, and troubleshooting.
- Can be published to various storage and analytics services.
Memory trick: Flow logs show who's going where, load balancer knows who comes by, storage logs who touched the file, VM console is just one guy.
Data Encryption Types
Flip cardMethods of securing data by transforming it into an unreadable format, categorized by whether the data is stored or being transmitted.
- Encryption at Rest: Data is encrypted when stored on physical media.
- Encryption in Transit: Data is encrypted when moving across networks.
- Both are often required for comprehensive security.
Memory trick: Resting data is safe, Traveling data is safe.
Risk Avoidance
Flip cardA risk response strategy that eliminates exposure to a risk entirely by not engaging in the activity or process that creates it.
- Removes the risk source completely
- Often used for unacceptable or catastrophic risks
- May limit business opportunities or efficiency gains
Memory trick: MATA: Mitigate, Avoid, Transfer, Accept
Point-in-Time Recovery
Flip cardThe ability to restore data to a specific, desired moment in time, often achieved by combining a full backup with subsequent incremental or differential backups.
- Minimizes data loss by restoring to a very specific point.
- Requires both a base backup and a sequence of changes.
- Crucial for transactional databases.
Memory trick: Full + Incremental = Perfect Time Restore.
Single Sign-On (SSO) / Federation
Flip cardAn IAM capability that allows users to authenticate once and gain access to multiple independent applications or systems without re-authenticating for each one.
- Often implemented via identity federation protocols like SAML or OAuth/OIDC
- Improves user experience and reduces password fatigue
- Relies on a trusted identity provider (IdP) shared across service providers
Memory trick: One badge (SSO) opens many doors across the building without swiping again at each one.
Continuous Integration (CI)
Flip cardA DevOps practice where developers frequently merge their code changes into a central repository, triggering automated builds and tests.
- Detects integration issues early.
- Improves code quality and team collaboration.
- Forms the first stage of a CI/CD pipeline.
Memory trick: Integrate, Deliver, Deploy: The CI/CD Way.
Exit Strategy / Data Portability Clause
Flip cardA contractual provision requiring a cloud provider to export customer data in a standard format and assist with migration upon contract termination, mitigating vendor lock-in.
- Should specify format, timeline, and assistance obligations
- Reduces dependency on proprietary provider technologies
- Best negotiated before signing the initial contract, not after
Memory trick: Pack an exit bag (portability clause) before moving into any cloud house so you can leave anytime.
Function as a Service (FaaS)
Flip cardA serverless computing model that allows developers to execute code in response to events without provisioning or managing servers, paying only for the compute resources consumed during execution.
- Event-driven execution.
- Automatic scaling and zero administration.
- Pay-per-execution billing (milliseconds of compute).
Memory trick: FaaS: Functions are Fast And Serverless.
Log Management Service
Flip cardA cloud service or platform designed to collect, centralize, process, analyze, and store operational logs from various applications and infrastructure components.
- Aggregates logs from distributed sources.
- Provides capabilities for search, filtering, and anomaly detection.
- Facilitates long-term retention and compliance.
- Essential for monitoring, troubleshooting, and security auditing.
Memory trick: Log Services are the Libraries of System Events.
Regulatory/Compliance Gap
Flip cardA discrepancy between an organization's existing legal, industry, or internal compliance requirements and the capabilities or responsibilities within a cloud environment.
- Often related to data residency, privacy, and security standards.
- Requires careful assessment and potential adjustments to policies or cloud architecture.
- Critical for industries like healthcare, finance, and government.
Memory trick: Gaps in Tech, Skills, Processes, and Rules.
Database Monitoring Metrics
Flip cardKey performance indicators (KPIs) tracked to assess the health, performance, and resource utilization of a database system.
- Crucial for identifying bottlenecks and performance issues.
- Includes metrics like connections, queries per second, latency, CPU, memory, and disk I/O.
- Proactive monitoring helps prevent outages and optimize performance.
Memory trick: To find a database bottleneck, think 'CON-Q-LOAD': CONnections, Queries, and overall LOAD.
Principle of Least Privilege
Flip cardA security best practice requiring that users, programs, or processes be granted only the essential permissions needed to perform their assigned task.
- Minimizes the attack surface and potential damage from compromise.
- Applies to human users and automated processes.
- Requires regular review and adjustment of permissions.
Memory trick: Give only the least key, then take it away.
SLA Availability Calculation
Flip cardCalculating the maximum allowable downtime for a given percentage of availability over a specific period (e.g., month or year).
- Availability % = (Total Time - Downtime) / Total Time * 100.
- Downtime = (100% - Availability %) * Total Time.
- Common SLA percentages: 99%, 99.9%, 99.99%, 99.999% ('nines').
Memory trick: SLA: Service Level Agreement, so 'Subtract Lost Always'.