CompTIA Cloud+ (CV0-004) flashcards
172 free flashcards. Tap a card to flip it.
Kubernetes Orchestration
Flip cardAn open-source system for automating deployment, scaling, and management of containerized applications, using declarative configuration.
- Manages container lifecycles across a cluster.
- Uses declarative YAML manifests to define desired state.
- Provides features like scaling, self-healing, and service discovery.
Memory trick: Kubernetes orchestrates clusters, Compose for single host, IaC builds infra, VM templates for VMs.
Distributed Tracing
Flip cardA technique used to monitor and observe requests as they flow through a distributed system, providing end-to-end visibility.
- Assigns a unique trace ID to each request.
- Captures timing and contextual data for each service interaction.
- Essential for debugging microservices and serverless architectures.
Memory trick: Tracing follows the 'Thread' of a request through the 'Web'.
Cloud Storage Tiers
Flip cardDifferent classes of cloud storage services optimized for cost, performance, and access frequency.
- Hot/Standard storage for frequently accessed data.
- Cool/Infrequent Access storage for less frequent access.
- Archive storage for long-term retention, rarely accessed.
Memory trick: Store smart: Hot is 'Now', Cold is 'Later', Archive is 'Forever'.
Trunk-Based Development
Flip cardA branching strategy where developers integrate small, frequent changes directly into a shared main branch, keeping feature branches short-lived to support continuous integration.
- Branches (if used) live hours, not weeks
- Reduces merge conflicts through frequent integration
- Pairs well with feature flags for incomplete work
Memory trick: Trunk-based: everyone plants back into the same tree trunk daily.
Canary Deployment
Flip cardA deployment strategy where a new version of an application is incrementally rolled out to a small subset of users, allowing for real-world testing and easy rollback.
- Reduces risk by exposing new code to a small audience first.
- Allows monitoring performance and errors in production.
- Enables quick rollback if critical issues are found.
Memory trick: Canary tests a few, Blue/Green switches all, Rolling updates gradually, Big Bang goes all at once.
Cost Optimization: Scheduling Off-Peak Shutdown
Flip cardA cloud cost optimization technique that involves automatically powering off non-production or non-critical resources during periods of low or no demand.
- Directly reduces compute costs by stopping billing for idle resources.
- Ideal for development, test, or non-critical environments.
- Requires applications to tolerate startup time after power-on.
Memory trick: Turn off the lights, save the bytes!
SSE-S3
Flip cardServer-Side Encryption where Amazon S3 manages both the encryption keys and the encryption process.
- Easiest to implement.
- No customer key management required.
- Keys are unique and rotated regularly by AWS.
Memory trick: Who holds the key determines the encryption choice.
IAM Roles for Cloud Resources
Flip cardIdentity and Access Management (IAM) roles are used to delegate temporary permissions to cloud resources (like VMs or serverless functions) to access other cloud services securely.
- Avoids embedding static credentials.
- Adheres to the principle of least privilege.
- Permissions are dynamically assumed by the resource.
Memory trick: IAM Roles: Identity Access Made Right for Resources.
Auto-Scaling Cooldown Period
Flip cardA configurable setting in an auto-scaling group that prevents additional scaling activities from being triggered immediately after a previous scaling event.
- Allows time for new instances to launch and warm up.
- Prevents rapid, unnecessary scaling actions (flapping).
- Typically lasts several minutes (e.g., 300 seconds/5 minutes).
Memory trick: Cooldown Prevents Quick Scale-Up.
Reserved Instances / Savings Plans
Flip cardCloud pricing models that provide significant discounts (e.g., 30-70%) on compute resources in exchange for a commitment to a specific instance type, region, or compute usage over a 1-year or 3-year term. Ideal for stable, predictable workloads.
- Commitment-based pricing for cost savings
- Suitable for predictable, long-running workloads
- Offers substantial discounts over On-Demand
- Less flexible than On-Demand, more flexible than Spot
Memory trick: On-demand is flexible, Spot is cheap but risky, Reserved is steady savings.
SAML (Security Assertion Markup Language)
Flip cardAn XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), enabling Single Sign-On (SSO).
- Enables Single Sign-On (SSO)
- Uses XML for assertions
- Commonly used for federated identity in cloud environments
Memory trick: SAML is like a digital passport for cloud apps.
Containers
Flip cardContainers are lightweight, standalone, executable packages of software that include everything needed to run an application: code, runtime, system tools, system libraries, and settings. They isolate applications from their environment and ensure consistent execution.
- Lightweight and portable
- Isolate applications and dependencies
- Consistent execution across environments
- Share the host OS kernel
Memory trick: Containers are like standardized shipping containers for software, always fitting and running anywhere.
Incident Response: Containment
Flip cardThe phase of the incident response process aimed at limiting the scope and impact of a security incident, preventing further damage, and isolating affected systems.
- Occurs immediately after identification/analysis.
- Focuses on stopping the spread of the incident.
- Examples: isolating networks, disabling accounts, stopping services.
Memory trick: Don't let the fire spread; put up a firewall!
VPC NACL Statelessness
Flip cardNetwork Access Control Lists (NACLs) are stateless firewalls operating at the subnet level, requiring explicit rules for both inbound and outbound traffic, even for return traffic of an established connection.
- Requires separate allow rules for inbound and outbound traffic.
- Does not automatically allow return traffic for connections.
- Default NACLs implicitly deny all inbound and outbound traffic if no allow rules are present.
Memory trick: NACLs are like a bouncer who forgets faces: you need a pass to get in AND a new pass to get out.
VPC Endpoint
Flip cardA private connection between your VPC and supported cloud services, allowing traffic to flow privately without traversing the public internet.
- Enhances security by keeping traffic within the cloud network.
- Can be interface endpoints (ENIs) or gateway endpoints (route table targets).
- Used for services like S3, DynamoDB, SQS, SNS, etc.
Memory trick: Private Subnet, No Gateway, Endpoints Only.
NACL vs. Security Group
Flip cardNetwork Access Control Lists (NACLs) are stateless subnet-level firewalls, while Security Groups are stateful instance-level firewalls.
- NACLs process rules in order; Security Groups process all rules.
- NACLs can deny traffic; Security Groups only allow traffic.
- Both are critical for granular network security in cloud environments.
Memory trick: Layered Security, Check Every Gate.
Deployment and Testing Phase
Flip cardThe stage in a cloud deployment lifecycle where the application is deployed to test environments and thoroughly validated against functional, performance, security, and scalability requirements.
- Includes functional, integration, performance, load, and security testing.
- Verifies disaster recovery and business continuity plans.
- Ensures readiness for production launch.
Memory trick: Plan, Provision, Deploy, Monitor, Optimize.
Database Sharding
Flip cardA type of horizontal partitioning that divides a large database into smaller, more manageable parts called 'shards', which are spread across multiple database servers to distribute workload and improve scalability.
- Distributes data and workload across multiple database instances.
- Primarily used to scale write-heavy applications.
- Reduces I/O contention and improves overall database performance.
Memory trick: To write more, slice the cake into smaller, shareable pieces.
NAT Gateway
Flip cardA managed Network Address Translation (NAT) service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances.
- Provides outbound internet access for private subnets.
- Hides private IP addresses behind a public IP.
- Managed service, highly available.
Memory trick: Gateways Guide Network Traffic Safely.
Standard Block Storage
Flip cardA type of storage that provides raw, unformatted volumes that can be attached to instances, offering high performance, low latency, and consistent IOPS for critical applications.
- Ideal for databases, boot volumes, and high-performance workloads.
- Offers persistent storage independent of the compute instance.
- Can be provisioned with specific IOPS and throughput characteristics.
Memory trick: For 'critical database' with 'high IOPS', 'Standard Block Storage' is the 'Best'.
Network Security Group (NSG)
Flip cardA virtual firewall that controls inbound and outbound network traffic to virtual machines or subnets within a cloud environment.
- Operates at the instance or subnet level.
- Defines rules for IP addresses, ports, and protocols.
- Is stateful, meaning it tracks connections.
Memory trick: NSG is like a personal bouncer for your cloud VMs.
Next-Generation Firewall (NGFW)
Flip cardAn advanced firewall that combines traditional firewall functions with additional capabilities like deep packet inspection, intrusion prevention, and application awareness.
- Deep packet inspection
- Intrusion prevention system (IPS) capabilities
- Application-level control
Memory trick: NGFW is the smart gatekeeper for all cloud network traffic.
Configuration Drift Detection
Flip cardThe process of comparing the live, running state of infrastructure against its intended definition in code to identify unauthorized or unintended changes.
- Terraform 'plan' command detects drift without applying changes
- Manual console changes are a common cause of drift
- Drift undermines the reliability of infrastructure-as-code
Memory trick: Before fixing anything, play detective and compare the blueprint to the actual building.
IOPS (Input/Output Operations Per Second)
Flip cardA common performance metric for storage devices, indicating the maximum number of read/write operations a storage device can handle per second.
- Higher IOPS means faster data access.
- Critical for databases and high-transaction applications.
- Cloud providers offer different storage tiers with varying IOPS capabilities.
Memory trick: Disk Maxed? Upgrade Storage Specs.
Git Tag
Flip cardA Git tag is a fixed reference pointing to a specific commit, commonly used to mark release versions such as v1.0.0.
- Tags do not move like branches do
- Often follow semantic versioning (major.minor.patch)
- Can be annotated with metadata or lightweight
Memory trick: Tag it like a luggage label so you can find that exact release again.
Cloud Security Posture Management (CSPM)
Flip cardCSPM tools continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and remediation guidance.
- Continuous monitoring
- Identifies misconfigurations and compliance issues
- Provides remediation guidance
Memory trick: CSPM is the cloud's continuous health check and security posture manager.
Cloud Resource Decommissioning
Flip cardThe systematic process of removing cloud resources (e.g., VMs, storage, networks) that are no longer needed, ensuring resource optimization and cost savings.
- Involves identifying unused resources.
- Requires validation of no dependencies before removal.
- Often includes steps like powering off, archiving, and then terminating.
Memory trick: Before you trash, check for a crash!
Lambda Resource-Based Policy
Flip cardA policy attached directly to an AWS Lambda function that defines which principals (users, roles, AWS services) can invoke or access the function.
- Controls invocation permissions.
- Uses JSON policy syntax.
- Managed directly on the Lambda function.
Memory trick: Lambda's policy is its bouncer.
Declarative Automation
Flip cardAn automation approach where the desired end state is specified, and the tool determines the steps needed to achieve and maintain that state.
- Contrasts with imperative automation's step-by-step commands
- Used by tools like Puppet, Terraform, and Kubernetes manifests
- Simplifies maintaining consistent, repeatable configurations
Memory trick: Declarative is telling a GPS your destination; imperative is reciting every turn yourself.
Strangler Fig Pattern
Flip cardA migration strategy where a new system gradually replaces specific functionalities of a legacy system, running alongside it until the old system is 'strangled' (retired).
- Ideal for complex, monolithic applications.
- Minimizes risk and downtime during migration.
- Allows for gradual modernization and cloud adoption.
Memory trick: Remembering Cloud's 6 R's for Right Migration.
Network Bandwidth Saturation
Flip cardA condition where the data transfer capacity of a network link or interface is fully utilized, leading to increased latency, packet loss, and retransmissions.
- Symptoms include high packet retransmission rates, increased latency, and timeouts.
- Often occurs when CPU/memory are normal, indicating a network-specific bottleneck.
- Can be mitigated by increasing network interface capacity or distributing traffic.
Memory trick: Low CPU, high retransmissions? Your network pipe is too small!
Localized Data Storage
Flip cardStoring data within specific geographic boundaries to comply with data residency regulations and ensure adherence to local laws and governance.
- Data stored within specific geopolitical regions
- Complies with data residency laws
- Supports multi-region regulatory adherence
Memory trick: Keep data where it belongs, region by region, for strict compliance.
Dedicated Hosts
Flip cardPhysical servers with EC2 instance capacity fully dedicated to your use.
- Provides visibility into physical host properties.
- Supports 'bring your own license' (BYOL) for certain software.
- Offers predictable performance and isolation.
Memory trick: Dedicated Hosts are your own private server room in the cloud, perfect for finicky licenses.
Multi-Data Point Alarm (M out of N)
Flip cardAn alarm configuration that triggers only when a metric exceeds a threshold for 'M' out of 'N' consecutive evaluation periods, preventing false positives from transient spikes.
- Requires sustained threshold breach to alert.
- Reduces alert fatigue from temporary fluctuations.
- Commonly used for critical performance metrics where consistency matters.
Memory trick: M-of-N: Multiple data points mean a real problem, not just a blip.
Kubernetes ImagePullBackOff
Flip cardA Kubernetes pod status indicating that the Kubelet on a node repeatedly failed to pull a container image from a registry, often due to authentication problems or image unavailability.
- Occurs when image cannot be pulled from the registry.
- Common causes include incorrect image name/tag, private registry authentication issues (image pull secrets), or network problems.
- Troubleshooting involves checking image name, registry access, and secrets.
Memory trick: Pod's trying to grab its clothes, but the closet's locked or empty.
Configuration Audit
Flip cardA systematic review of security settings, configurations, and baselines to ensure compliance with established policies and identify deviations.
- Reviews system configurations
- Compares against baselines/policies
- Identifies compliance deviations
Memory trick: Configuration Audit: The detailed checklist for cloud settings.
Database Migration Service (DMS) with CDC
Flip cardA cloud service that enables continuous migration of databases to the cloud, using Change Data Capture (CDC) for ongoing synchronization.
- Supports homogeneous and heterogeneous migrations.
- Minimizes downtime for critical databases.
- Automatically captures and applies changes from source to target.
Memory trick: DMS + CDC: Data moves continuously.
Cloud Egress Costs
Flip cardCharges incurred for data transferred out of a cloud provider's network or between different regions/zones.
- Often a significant hidden cost in cloud computing.
- Data transfer within the same region/availability zone is typically free or very cheap.
- Optimizing data locality is key to reducing egress costs.
Memory trick: Keep data and compute 'Close' to keep costs 'Low'.
Cache Invalidation
Flip cardThe process of removing or updating stale data from a cache to ensure that users always receive the most current information.
- Crucial for maintaining data consistency.
- Can be explicit (application-driven) or time-based (TTL).
- Poor invalidation leads to stale data issues.
Memory trick: Invalidate Cache, Keep Data Fresh.
Multi-Region Active/Passive DR
Flip cardMulti-Region Active/Passive disaster recovery involves deploying a full production environment in one primary geographical region (active) and a scaled-down, but fully functional, replica in a secondary region (passive/standby). In a disaster, traffic is failed over to the secondary region, which then scales up to full capacity.
- One region active, serving traffic
- Another region passive/standby, scaled down but ready
- Provides recovery from regional outages
- Lower RTO than Pilot Light, higher than Active/Active
Memory trick: Active/Passive is like having a fully-stocked, ready-to-open duplicate store in another city.
Transit Gateway
Flip cardA Transit Gateway is a network transit hub that you can use to interconnect your Virtual Private Clouds (VPCs) and on-premises networks. It scales to thousands of VPCs, simplifies network management, and supports cross-region connectivity.
- Central network hub for VPCs and on-premises networks
- Simplifies complex network topologies (hub-and-spoke)
- Scales to thousands of VPCs
- Supports cross-region connectivity
Memory trick: Transit Gateway is the 'traffic control tower' for your sprawling cloud network, centralizing all connections.
Data Sovereignty
Flip cardThe concept that digital data is subject to the laws and regulations of the country or region where it is stored or processed, often impacting data residency and cross-border data transfers.
- Data is subject to local laws where it resides.
- Crucial for regulatory compliance (e.g., GDPR, CCPA).
- Influences choice of cloud regions and data transfer policies.
Memory trick: Sovereignty: Data's country, data's rules.
Asynchronous Cross-Region Replication
Flip cardA data replication method where data is copied to a remote region after being committed locally, offering disaster recovery with a Recovery Point Objective (RPO) greater than zero.
- Protects against regional outages and disasters.
- Tolerates higher latency between regions.
- Involves potential for some data loss (RPO > 0).
Memory trick: To survive a 'Regional' disaster, you need 'Asynchronous' 'Replication' far away.
Cloud Migration Strategies (6 Rs)
Flip cardA framework for categorizing different approaches to moving applications and data to the cloud.
- Re-hosting (Lift and Shift) involves minimal changes.
- Re-platforming involves some cloud-native optimizations.
- Re-factoring involves significant architectural changes.
Memory trick: Re-host, Re-platform, Re-factor, Re-purchase, Retire, Retain — the 'Rs' of migration.
Customer Managed Key (CMK) with HSM
Flip cardAn encryption key management strategy where the customer generates and controls their encryption keys, often using a Hardware Security Module (HSM) for enhanced security and control, even when the data is stored in the cloud.
- Customer retains full control over key lifecycle.
- HSMs provide tamper-resistant hardware for key storage.
- Meets stringent compliance requirements for key ownership.
Memory trick: My Keys, My Rules: HSM is the ultimate lockbox.
Serverless Functions (FaaS)
Flip cardA compute execution model where the cloud provider dynamically manages the allocation and provisioning of servers. Developers write and deploy code (functions) that are executed in response to events, without managing the underlying infrastructure.
- Event-driven execution
- Automatic scaling and elasticity
- Pay-per-execution billing model
- Stateless by design
Memory trick: Serverless scales with a snap, VMs need a map.
S3 Bucket Policies
Flip cardResource-based access policies attached directly to an S3 bucket to control who has access to the bucket and its objects.
- JSON-based policy language.
- Can grant or deny permissions.
- Evaluated with IAM policies for final access decisions.
Memory trick: Bucket policies are the bouncers for your S3 club.
Server-Side Encryption with Customer-Provided Keys (SSE-C)
Flip cardAn encryption method where the customer provides their own encryption keys to the cloud service, which then uses these keys to encrypt and decrypt data at rest on the server side.
- Customer provides the encryption key for each object operation.
- Cloud provider does not store the customer-provided key.
- Offers exclusive customer control over key lifecycle for data at rest.
Memory trick: SSE-C: Customer's Secret, Cloud Encrypts.
Orchestration Templates
Flip cardDeclarative files (e.g., JSON, YAML) used to define and provision a collection of cloud resources as a single unit or 'stack'.
- Enable Infrastructure as Code (IaC).
- Automate deployment of complex, multi-resource applications.
- Ensure consistency and repeatability of environments.
Memory trick: Automation Builds Complex Stacks with Templates.
Network ACLs/Security Groups
Flip cardVirtual firewalls that control inbound and outbound traffic for network interfaces or instances in a cloud environment.
- Operate at the instance or subnet level.
- Can be stateful or stateless.
- Used to filter traffic based on IP address, port, and protocol.
Memory trick: Connect Safely, Rules Apply to Everyone
RPO and RTO
Flip cardRecovery Point Objective (RPO) defines the maximum acceptable data loss, while Recovery Time Objective (RTO) defines the maximum acceptable downtime.
- RPO is measured in time (e.g., 1 hour, 1 day).
- RTO is measured in time (e.g., 2 hours, 12 hours).
- Lower RPO/RTO typically requires more complex and costly solutions.
Memory trick: RPO is 'Point' of data lost, RTO is 'Time' to get back online.
Security Information and Event Management (SIEM)
Flip cardA solution that aggregates and analyzes security event data from various sources (logs, network devices, applications) to provide real-time threat detection, security monitoring, and compliance reporting.
- Centralizes security logging.
- Correlates events to identify threats.
- Supports compliance and incident response.
Memory trick: SIEM: Security Insights Every Minute.
Storage Lifecycle Management
Flip cardThe process of managing data throughout its lifecycle by automatically transitioning it between different storage classes (tiers) based on access patterns and retention requirements to optimize cost and performance.
- Automates data movement to colder, cheaper storage tiers.
- Balances cost, performance, and compliance needs.
- Crucial for managing large datasets with varying access frequencies.
Memory trick: Hot data is fast, cold data will last (cheaply).
Synchronous Replication (RPO=0)
Flip cardA data replication method where data is written to both the primary and secondary storage locations (often in different regions) simultaneously. A transaction is not considered complete until all replicas confirm the write, ensuring zero data loss (RPO=0) but potentially introducing latency.
- Guarantees RPO (Recovery Point Objective) of zero
- Data is written to all replicas before commit
- Ensures no data loss during failover
- Can introduce write latency across long distances
Memory trick: Synchronous writes, zero loss, multi-region boss.
Template Input Parameters
Flip cardVariables defined within an Infrastructure as Code (IaC) template that allow users to provide custom values at deployment time.
- Enhance template reusability and flexibility.
- Enable customization without modifying the template file.
- Can have default values and validation rules.
Memory trick: Templates Use Parameters for Customization.
Blue/Green Deployment
Flip cardA deployment strategy that runs two identical production environments (Blue and Green) and switches live traffic between them.
- Provides zero-downtime deployments.
- Enables instant rollback to the previous stable version.
- Requires double the infrastructure resources during deployment.
Memory trick: Blue/Green: Like 'Traffic Lights', switch instantly.
Golden Image (Custom Machine Image)
Flip cardA pre-configured virtual machine image that includes a hardened operating system, required software, security agents, and specific configurations, used as a template for new VM deployments.
- Ensures consistency and compliance.
- Reduces manual configuration errors.
- Speeds up VM provisioning and deployment.
Memory trick: Golden Image: Bake in security, deploy with ease.
Artifact Repository
Flip cardA centralized storage system that holds versioned build outputs (binaries, packages, libraries) produced by a CI pipeline for later retrieval and deployment.
- Examples: JFrog Artifactory, Sonatype Nexus, GitHub Packages
- Supports versioning and dependency resolution
- Sits between build/test stages and deployment stage
Memory trick: Artifact repository is the warehouse where finished packages wait for shipping.
Network Security Groups (NSGs)
Flip cardVirtual firewalls that control inbound and outbound traffic to network interfaces (VMs) or subnets in a cloud environment.
- Define rules for allowed/denied traffic.
- Operate at Layer 4 (TCP/UDP) and Layer 3 (IP).
- Provide granular network isolation and security.
Memory trick: Secure Network Zones Keep Everything Safe.
Multi-region Deployment
Flip cardDeploying an application across multiple geographically separate cloud regions to enhance fault tolerance, disaster recovery, and reduce latency for globally distributed users.
- Increases fault tolerance beyond a single region or Availability Zone.
- Provides disaster recovery capabilities against regional outages.
- Can reduce latency for users by serving them from a closer region.
Memory trick: Global Cloud Scales for Reliability and Speed.