CompTIA Cloud Essentials+ (CLO-002) flashcards
134 free flashcards. Tap a card to flip it.
Cloud Governance Policy Engine
Flip cardA system that defines, evaluates, and enforces compliance rules and security policies across cloud resources, often automatically remedying non-compliant configurations.
- Provides automated policy enforcement.
- Ensures continuous compliance and security.
- Reduces manual overhead and human error.
Memory trick: Policies Guard All Cloud Boundaries.
Service Level Agreement (SLA)
Flip cardA contract between a service provider and a customer that specifies the level of service expected, including performance metrics, availability, security, and responsibilities, along with penalties or remedies for non-compliance.
- Defines service quality and expectations
- Includes metrics, responsibilities, and remedies
- Crucial for managing cloud vendor relationships
Memory trick: MSA is the big book, SLA is the chapter on service quality.
Snapshot Backup
Flip cardA point-in-time copy of data or a system's state, used for recovery from data loss or corruption.
- Captures data rapidly without interrupting operations.
- Allows for quick restoration to a previous state.
- Essential for disaster recovery and operational continuity.
Memory trick: Protect your data with snapshots for a quick trip back in time.
Direct Cloud Connectivity
Flip cardA dedicated, private network connection established between a customer's on-premises infrastructure and a cloud provider's network, bypassing the public internet.
- Provides consistent, higher bandwidth and lower latency.
- Enhances security by avoiding the public internet.
- Can reduce data transfer costs for high volumes.
Memory trick: VPN-DCC: Very Pretty Networks Directly Connect Clouds.
Cloud Egress Costs
Flip cardCharges incurred for transferring data out of a cloud provider's network or from one region to another.
- Often a significant and unexpected cloud expense.
- Varies by region and destination.
- Can be optimized by co-locating resources or using CDNs for external delivery.
Memory trick: Data leaving costs money, keep it close.
Data Loss Prevention (DLP)
Flip cardA security technology that monitors, detects, and blocks unauthorized transmission or exposure of sensitive data across networks, endpoints, and storage.
- Scans data in motion, at rest, and in use
- Uses pattern matching (e.g., regex for SSNs, card numbers)
- Acts as both a detective and preventive control
- Helps enforce data classification policies
Memory trick: 'DLP is the bouncer at the data door' checking for sensitive patterns.
Business Associate Agreement (BAA)
Flip cardA HIPAA-required contract between a covered entity and any third party (business associate) that creates, receives, maintains, or transmits PHI on its behalf.
- Legally mandated under the HIPAA Privacy Rule
- Outlines safeguards and breach notification duties
- Cloud providers storing ePHI must sign a BAA before onboarding
Memory trick: BAA = 'Before Any Access' to PHI, sign the agreement
Data Masking
Flip cardA technique that replaces sensitive data with fictitious but structurally realistic values, typically irreversibly, to protect data used in non-production environments like testing and development.
- Often irreversible, unlike tokenization
- Preserves data format/structure for functional testing
- Commonly used in dev/test/QA environments
- Reduces exposure of real sensitive data outside production
Memory trick: 'Masking wears a costume' — data looks real but the true face is gone forever.
Tokenization (PCI DSS)
Flip cardA technique that replaces sensitive cardholder data with a non-sensitive placeholder token, reducing the systems in scope for PCI DSS compliance.
- Tokens have no exploitable value if stolen
- Reduces number of systems requiring PCI DSS audit
- Different from encryption, which is reversible with a key
Memory trick: Token = a 'fake coin' that's worthless to thieves
Preventive Control
Flip cardA security control designed to stop a security incident or unauthorized activity before it can occur.
- Examples: firewalls, encryption, access control lists
- Acts proactively, before an event happens
- Contrasts with detective controls, which act during/after an event
Memory trick: PDC-C: Prevent the fire, Detect the smoke, Correct the damage, Compensate if the sprinkler is broken.
Process Gap
Flip cardA discrepancy between an organization's current operational workflows and procedures and the new processes required by a cloud environment or solution.
- Mismatch in operational procedures
- Requires workflow re-engineering
- Often involves training and adoption
Memory trick: When looking for cloud gaps, check your Tech, Security, Compliance, and how you Process everything.
Cloud Regions and Availability Zones
Flip cardGeographically distinct locations (Regions) hosting multiple isolated data centers (Availability Zones) to provide global reach, high availability, and disaster recovery for cloud services.
- Regions offer geographic proximity for low latency.
- Availability Zones provide fault isolation within a region.
- Crucial for high availability, disaster recovery, and compliance.
Memory trick: Regions are big lands, Zones are safe sands.
SLA Downtime Calculation (High Uptime)
Flip cardCalculating maximum allowed service outage for very high uptime percentages (e.g., 'four nines' or 99.99%) over extended periods like a year.
- High uptime percentages mean very little allowed downtime.
- Accurate calculation requires precise total minutes in the period.
- Rounding to the nearest minute is often required for practical reporting.
Memory trick: Percent up, then time down, to keep the service sound.
Managed Services
Flip cardOutsourcing the responsibility for maintaining, monitoring, and managing IT infrastructure or cloud services to a third-party provider.
- Reduces operational burden for the client.
- Often includes proactive monitoring, patching, and security.
- Allows clients to focus on core business functions.
Memory trick: Managed means someone else's hand, keeps your cloud in demand.