CompTIA Cloud+ (CV0-004) flashcards
172 free flashcards. Tap a card to flip it.
Continuous Integration (CI)
Flip cardCI is the practice of frequently merging code into a shared repository, with each merge automatically built and tested to catch integration issues early.
- Encourages small, frequent commits
- Automated build and test pipeline runs on each commit
- Reduces integration conflicts and catches bugs early
Memory trick: Commit, Build, Test, Deploy — CI catches problems before they snowball.
Containerization
Flip cardA lightweight virtualization technology that packages an application and all its dependencies into a portable, isolated unit (container), enabling rapid deployment and efficient scaling.
- Increases portability and consistency across environments.
- Faster startup and scaling than virtual machines.
- Efficient resource utilization by sharing the host OS kernel.
Memory trick: For 'quick' 'scaling' of a 'packaged' app, 'Containers' are the 'King'.
Direct Connect / ExpressRoute
Flip cardCloud services (AWS Direct Connect, Azure ExpressRoute) that establish a dedicated, private network connection from an on-premises data center or a co-location environment to a cloud provider's network.
- Provides consistent high bandwidth and lower latency than internet-based VPNs.
- Crucial for hybrid cloud architectures and cross-region data synchronization.
- Offers enhanced security and reliability.
Memory trick: Direct Connect links regions fast, VPNs are over the internet, CDNs cache, GLBs route users.
Storage Tiering
Flip cardA data management strategy that automatically moves data between different storage classes or 'tiers' based on predefined policies, typically related to access frequency, performance requirements, and cost.
- Optimizes storage costs by matching data value to storage cost.
- Utilizes different storage classes (e.g., hot, warm, cold, archive).
- Automated policies manage data movement.
Memory trick: Tiering saves money by moving data, Replication protects, Dedupe shrinks, Snapshots recover.
Incident Response: Eradication
Flip cardThe incident response phase following containment, focused on removing the root cause of the incident and eliminating all traces of the attacker from the environment.
- Follows containment
- Removes root cause
- Eliminates attacker presence (e.g., rogue accounts, backdoors)
Memory trick: Prepare, ID, Contain, Eradicate, Recover, Lessons Learned – a security cleanup cycle.
Web Application Firewall (WAF)
Flip cardA security solution that protects web applications from common web exploits and vulnerabilities by filtering and monitoring HTTP traffic.
- Operates at Layer 7 (application layer).
- Provides deep packet inspection of HTTP/S requests.
- Protects against SQL injection, XSS, and other web attacks.
Memory trick: WAF: Web App's Fine-grained Filter.
Patch Management
Flip cardThe process of identifying, acquiring, testing, and applying software patches (updates, bug fixes, security fixes) to systems.
- Crucial for security and stability.
- Can be complex in diverse environments.
- Automation and centralized tools improve efficiency.
Memory trick: Centralized CI/CD: The 'Patch' to automate and secure diverse clouds.
Direct Connect
Flip cardDirect Connect is a cloud service solution that creates a dedicated network connection from your on-premises datacenter to a cloud provider's network. This bypasses the public internet, offering consistent network performance, reduced costs, and enhanced security.
- Dedicated, private network connection
- Bypasses the public internet
- Consistent network performance
- Enhanced security
Memory trick: Direct Connect is like laying down a private fiber cable from your office to the cloud.
Multi-Cloud Vulnerability Management
Flip cardThe practice of identifying, assessing, and remediating security vulnerabilities across multiple distinct cloud provider environments using a unified approach or toolset.
- Requires compatibility with various cloud APIs and services.
- Aims for consistent security posture across diverse clouds.
- Often involves centralized reporting and remediation tracking.
Memory trick: One tool, many clouds: Compatibility is key.
Rehost (Lift-and-shift)
Flip cardMigrating an application to the cloud with minimal or no changes to its architecture or code, essentially moving it 'as is'.
- Fastest migration path.
- Minimizes risk and complexity.
- Often the first step in cloud adoption for legacy apps.
Memory trick: Remember the 6 Rs for cloud migrations.
Auto-Scaling Policy Responsiveness
Flip cardThe ability of an auto-scaling group's policies to quickly and effectively add or remove instances in response to changes in application workload, preventing resource exhaustion or over-provisioning.
- Crucial for handling variable traffic patterns.
- Slow scaling can lead to performance degradation (e.g., 503 errors) during spikes.
- Factors include cooldown periods, metric thresholds, and instance launch times.
Memory trick: Traffic surge, but the scaling taxi isn't fast enough.
Push-Based Configuration Management
Flip cardA configuration management model where a central server actively initiates connections and sends configuration changes to managed nodes on demand.
- Server-initiated, on-demand execution
- Common with Ansible in default mode and SaltStack push mode
- Contrasts with pull-based agents (e.g., Puppet/Chef default) that poll a master
Memory trick: Push = the boss walks the memo to your desk; Pull = you check the mailbox.
Patch Management Automation
Flip cardThe automated process of identifying, acquiring, testing, and applying software updates and security patches to systems and applications.
- Ensures systems are up-to-date with the latest security fixes.
- Reduces manual effort and human error.
- Often includes scheduling, reporting, and rollback capabilities.
Memory trick: Patching is a pain, let automation take the strain.
Horizontal Scaling
Flip cardAdding more instances of a resource (e.g., servers, VMs) to distribute the workload and handle increased demand.
- Also known as 'scaling out'.
- Ideal for stateless applications.
- Increases fault tolerance and capacity.
Memory trick: Horizontally, you add more friends to the party; Vertically, you make one friend bigger.
Federated Identity Management
Flip cardA system that allows users to access multiple applications and services using a single set of login credentials, managed by a trusted identity provider, often spanning different security domains.
- Enables Single Sign-On (SSO).
- Promotes consistent policy enforcement.
- Simplifies user provisioning/deprovisioning across systems.
Memory trick: Federation: One ID to rule them all, on-prem and cloud.
Canary Release
Flip cardA deployment strategy where a new version of an application is released to a small subset of users first, before being rolled out to the entire user base.
- Minimizes risk by limiting exposure to potential issues.
- Allows real-world testing and performance monitoring.
- Enables quick rollback if problems are detected.
Memory trick: Canary sings first, then the flock follows.
NACLs (Network Access Control Lists)
Flip cardStateless, subnet-level firewalls that control inbound and outbound traffic to and from subnets in a VPC.
- Operate at the network perimeter (subnet level).
- Stateless - separate rules for inbound/outbound.
- Effective for coarse-grained IP-based filtering.
Memory trick: NACLs guard the subnet's network gates.
Envelope Encryption
Flip cardA method where data is encrypted with a data encryption key (DEK), and the DEK itself is then encrypted with a key encryption key (KEK), providing layered security and access control.
- Uses both DEK and KEK
- KEK encrypts the DEK
- Application uses encrypted DEK for data operations
Memory trick: Keys within keys, like an encrypted envelope for your secrets.
Feature Flag
Flip cardA runtime configuration switch that enables or disables a specific application feature without requiring code redeployment.
- Allows instant rollback of a single feature
- Supports gradual feature rollout (feature flagging)
- Decouples deployment from feature release timing
Memory trick: A feature flag is a light switch on the wall you can flip off instantly, no rewiring needed.
Horizontal Pod Autoscaler (HPA) Formula
Flip cardKubernetes HPA calculates the desired replica count as the ceiling of current replicas multiplied by the ratio of current metric value to target (desired) metric value.
- Formula: ceil(currentReplicas × currentMetric/desiredMetric)
- Always rounds up to avoid under-provisioning
- Commonly driven by CPU or custom metrics
Memory trick: HPA always rounds UP - like a bouncer letting in extra pods just in case.
Dedicated Instance
Flip cardA Dedicated Instance is a virtual machine instance that runs on hardware dedicated to a single customer. While it's still a virtualized environment, it ensures that your instances are physically isolated from instances belonging to other customers.
- Virtual instances on hardware dedicated to a single customer
- Provides physical isolation from other customers' workloads
- Offers enhanced security and compliance for sensitive data (e.g., PII)
- Does not provide granular control over host placement or specific hardware (unlike Dedicated Hosts)
Memory trick: Dedicated Instances are like having your own 'private floor' in a shared building – still virtual, but no sharing with other tenants.
Rolling Deployment
Flip cardA deployment strategy that gradually replaces instances of an old application version with a new version in small batches to maintain availability.
- Updates a subset of servers/pods at a time
- Minimizes downtime compared to full cutover
- Rollback requires reversing the batch process
Memory trick: Rolling stone gathers no downtime - it moves batch by batch.
Target Tracking & Scheduled Scaling
Flip cardTwo distinct auto-scaling policies: Target Tracking maintains a desired metric level, while Scheduled Scaling adjusts capacity at predefined times.
- Target Tracking: Reactive to real-time metrics (e.g., CPU, network).
- Scheduled Scaling: Proactive for predictable load changes.
- Combined for optimal cost and performance in varied workloads.
Memory trick: Track targets, schedule peaks.
Reconciliation Loop
Flip cardAn orchestration mechanism where a controller continuously observes the current state, compares it to the desired state, and takes corrective action to align them.
- Core mechanism in Kubernetes controllers
- Enables self-healing infrastructure
- Automatically corrects deviations from manifest-defined state
Memory trick: Kubernetes is a thermostat: it keeps checking and adjusting until the room matches the set temperature.
Centralized Logging
Flip cardThe practice of collecting logs from all systems and applications into a single, centralized platform for easier management, analysis, and monitoring.
- Crucial for distributed systems.
- Enables comprehensive search and analysis.
- Simplifies troubleshooting and compliance.
Memory trick: Logs are 'Collected', 'Parsed', 'Analyzed', then 'Archived'.
WORM/Object Lock
Flip cardA feature in cloud object storage that makes data immutable for a specified retention period, preventing it from being overwritten or deleted, crucial for compliance and legal hold requirements.
- Ensures data integrity and non-repudiation.
- Commonly used for regulatory compliance (e.g., SEC 17a-4, FINRA).
- Data cannot be modified or deleted until the retention period expires.
Memory trick: WORM locks your data like a vault, write once, read many.
Archive Object Storage
Flip cardA storage class optimized for extremely infrequent access and long-term data retention, offering the lowest storage costs but with higher retrieval costs and longer retrieval times.
- Ideal for compliance, regulatory, and disaster recovery archives.
- Retrieval times can be minutes to hours.
- Lowest cost per GB stored.
Memory trick: Archive storage is like putting old files in a deep, cheap, but slow-to-access vault.
Data Residency
Flip cardThe requirement for data to be stored and processed within specific geographic boundaries, often dictated by legal or regulatory compliance.
- Crucial for many industry and government regulations.
- Determined by the physical location of data centers.
- Cloud regions and availability zones are key to achieving this.
Memory trick: Residency is about the house, not the locks or the road.
VPC Subnet Design (Multi-tier)
Flip cardStructuring subnets within a Virtual Private Cloud to segregate application tiers based on their internet accessibility and security requirements.
- Public subnets: internet-facing resources.
- Private subnets: internal resources, no direct internet access.
- Enhances security by limiting exposure of sensitive data/logic.
Memory trick: Public for show, Private for dough (data).
Pipeline as Code
Flip cardThe practice of defining a CI/CD pipeline's stages, steps, and triggers in a text file stored in version control, enabling review and history tracking of pipeline changes.
- Examples: Jenkinsfile, .gitlab-ci.yml, GitHub Actions workflow YAML
- Stored alongside application source code
- Allows pipeline changes to be reviewed like application code
Memory trick: Pipeline as code: the recipe for baking your app lives in the same cookbook as the ingredients.
Cloud Access Security Broker (CASB)
Flip cardA CASB is a security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed.
- Provides visibility into cloud usage.
- Ensures compliance with data protection regulations.
- Prevents data loss (DLP capabilities).
- Protects against malware and threats.
Memory trick: CASB is the 'C'entral 'A'gent for 'S'ecuring 'B'oth access and data in the cloud.
Service Mesh (mTLS)
Flip cardA service mesh provides a transparent layer for microservices to enable features like mutual TLS (mTLS) for encrypted and authenticated inter-service communication, without requiring application code changes.
- Automates mTLS and encryption for service-to-service traffic.
- Decouples security concerns from application logic.
- Enhances observability and policy enforcement for microservices.
Memory trick: Mesh weaves mTLS into every service call.
Incident Response: Recovery
Flip cardThe phase in the incident response lifecycle where affected systems are restored to normal operation, validated for functionality and security, and hardened to prevent future incidents.
- Follows the Eradication phase.
- Includes restoring data from backups.
- Involves testing and continuous monitoring.
Memory trick: Please Don't Contain Every Raging Problem.
Key Management Service (KMS)
Flip cardA cloud service that provides centralized control over the lifecycle of cryptographic keys, including generation, storage, rotation, and access management.
- Manages symmetric and asymmetric keys.
- Integrates with other cloud services for encryption.
- Provides audit trails for key usage.
Memory trick: IAM Knights Guard Many Secret Keys.
Intrusion Prevention System (IPS)
Flip cardAn IPS is a network security device that monitors network and/or system activities for malicious policy violations and can automatically react to block or prevent detected threats in real-time.
- Combines detection (IDS) with active prevention capabilities.
- Analyzes traffic for signatures and anomalies.
- Can drop malicious packets, reset connections, or block source IPs.
Memory trick: IPS prevents, IDS just informs.
VPC Endpoint Condition
Flip cardA VPC endpoint condition in a cloud resource policy restricts access to resources (e.g., storage buckets, databases) to only requests originating through a specified Virtual Private Cloud (VPC) endpoint.
- Forces traffic over a private network path, bypassing the public internet.
- Enhances security for sensitive data by preventing direct internet exposure.
- Used in conjunction with other access policies (e.g., bucket policies).
Memory trick: VPC endpoints are the ONLY private doors to your data.
Multi-Cloud CSPM
Flip cardA Cloud Security Posture Management (CSPM) solution designed to provide unified visibility, compliance monitoring, and security enforcement across multiple public and private cloud environments.
- Centralized security posture visibility for diverse clouds.
- Enforces consistent security policies and baselines.
- Detects misconfigurations and compliance violations.
- Often includes automated remediation capabilities.
Memory trick: CSPM: 'C'onsistent 'S'ecurity 'P'olicy 'M'anager for all clouds.
Hashing for Integrity
Flip cardHashing is a cryptographic process that transforms data into a fixed-size string of characters (a hash value or digest), which is unique for each unique input, used to verify data integrity.
- Any change to input data results in a different hash output.
- One-way function; computationally infeasible to reverse.
- Commonly used to detect accidental or malicious data alteration.
Memory trick: Hashing verifies data's intact state.
SSE-KMS
Flip cardServer-Side Encryption with KMS (Key Management Service) Managed Keys encrypts data at rest using keys stored and managed within the cloud provider's KMS, specific to the customer's account.
- Keys are unique to the customer account.
- KMS provides auditing and key rotation.
- Cloud provider manages the KMS infrastructure.
- Offers more control than SSE-S3, less than SSE-C.
Memory trick: KMS: 'K'eys 'M'anaged by 'S'ervice, specific to 'K'ustomer.
Software Composition Analysis (SCA)
Flip cardSCA tools analyze an application's codebase to identify all open-source and third-party components, detect known vulnerabilities (CVEs), and assess licensing risks associated with them.
- Focuses on third-party and open-source components.
- Identifies known vulnerabilities (CVEs).
- Integrates into CI/CD pipelines.
- Crucial for container security and supply chain risk management.
Memory trick: SCA 'S'cans 'C'ontainers for 'A'll known vulnerabilities in their parts.
Customer Managed Keys (CMK) with HSM
Flip cardA key management model where customers generate, store, and manage their encryption keys within a dedicated Hardware Security Module (HSM) provided by the cloud vendor, ensuring high levels of security and regulatory compliance.
- Keys are isolated within a FIPS 140-2 Level 3 compliant HSM.
- Cloud provider cannot access plaintext keys.
- Customer retains full control over key lifecycle.
- Often used for highly regulated industries and sensitive data.
Memory trick: CMK with HSM: Customer's Keys, Hardware's Security, My Control.
HSM as a Service for Regional Keys
Flip cardA cloud service offering dedicated, tamper-resistant hardware security modules (HSMs) for cryptographic operations and key storage, often with guarantees for physical location and isolation.
- Provides highest assurance for key security and sovereignty.
- Keys generated and stored in FIPS 140-2 Level 3+ validated hardware.
- Helps meet strict regulatory compliance for key management.
Memory trick: HSMs Hold High Sovereignty Standards Securely.
SAML for Federated SSO
Flip cardSecurity Assertion Markup Language (SAML) is an open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), enabling single sign-on (SSO) in federated environments.
- XML-based protocol.
- Enables cross-domain SSO.
- Separates authentication (IdP) from service consumption (SP).
- Widely adopted in enterprise and cloud environments for federation.
Memory trick: SAML is the 'S'ingle 'A'nswer for 'M'ulti-organization 'L'ogins.
S3 Bucket Policy with VPC Endpoint Condition
Flip cardAn AWS S3 Bucket Policy that uses condition keys like `aws:SourceVpc` and `aws:SourceVpce` to restrict access to the bucket only when requests originate from a specified Virtual Private Cloud (VPC) or VPC Endpoint.
- Enforces private access to S3 from within a VPC.
- Prevents data exfiltration by blocking public internet access.
- Increases security and compliance for sensitive S3 data.
Memory trick: Bucket Policies Block Bad Broad Browsing.
SSE-KMS (Server-Side Encryption with KMS-Managed Keys)
Flip cardA server-side encryption method where the cloud provider's Key Management Service (KMS) manages the encryption keys, offering enhanced security features, auditability, and integration with IAM.
- Keys are managed by the cloud provider's KMS.
- Provides an audit trail of key usage.
- Integrates with IAM for granular access control.
Memory trick: KMS Keeps Medical Secrets Safe.
Resource-Based Policy (Serverless)
Flip cardA policy attached directly to a cloud resource (like a serverless function, S3 bucket, or SQS queue) that specifies which principals (users, roles, other services) have permissions to access that resource and what actions they can perform.
- Attached directly to the resource.
- Defines permissions 'on' the resource.
- Often used in conjunction with identity-based policies.
- Crucial for cross-account access and service-to-service permissions.
Memory trick: Resource Policies: 'R'estrict 'P'ermissions on the 'R'esource itself.
Attribute-Based Access Control (ABAC)
Flip cardABAC is an authorization system that grants access based on attributes of the user, resource, and environment, allowing for highly granular and dynamic access policies.
- Uses 'who, what, which, conditions' for access decisions.
- More flexible and scalable than RBAC for complex environments.
- Policies are defined using logical expressions of attributes.
Memory trick: ABAC uses ALL attributes for access, not just roles.
WORM Storage for Audit Logs
Flip cardWrite Once Read Many (WORM) storage is a data storage paradigm that allows data to be written to a storage device once and prevents the data from being overwritten or erased, ensuring immutability for compliance and auditing.
- Data cannot be modified or deleted after being written.
- Essential for regulatory compliance (e.g., HIPAA, FINRA).
- Used for audit logs, legal holds, and archival data.
- Implemented via features like 'Object Lock' in cloud object storage.
Memory trick: WORM: 'W'rite 'O'nce, 'R'ead 'M'any, 'N'o 'M'odifications.
Dedicated Cloud Connectivity
Flip cardDedicated cloud connectivity services (e.g., AWS Direct Connect, Azure ExpressRoute) establish a private, high-bandwidth network connection between an on-premises data center and a cloud provider's network, bypassing the public internet.
- Bypasses public internet for enhanced security and performance.
- Offers consistent network throughput and lower latency.
- Ideal for hybrid cloud architectures and large data transfers.
Memory trick: Direct routes are Express for Interconnecting your cloud.
OpenID Connect (OIDC)
Flip cardOpenID Connect (OIDC) is an authentication layer built on top of the OAuth 2.0 framework, enabling clients to verify the identity of the end-user and obtain basic profile information.
- Authentication protocol (unlike OAuth 2.0 which is authorization).
- Uses JSON Web Tokens (JWTs) for identity claims.
- Ideal for consumer-facing and enterprise SaaS applications.
- Enables single sign-on (SSO) and federated identity.
Memory trick: OIDC: 'O'pen 'I'dentity for 'D'ifferent 'C'redentials, easy SSO.
Private Link / Service Endpoint
Flip cardA cloud networking feature that enables private connectivity to services hosted on the same cloud platform, without exposing traffic to the public internet.
- Connects VPCs/VNets to services privately.
- Traffic remains within the cloud provider's network.
- Enhances security and simplifies network architecture.
Memory trick: Private Links Prevent Public Leaks.
Data Loss Prevention (DLP)
Flip cardData Loss Prevention (DLP) refers to a set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
- Identifies and classifies sensitive information.
- Monitors data movement across networks, endpoints, and cloud storage.
- Enforces policies to prevent unauthorized data transfer or sharing.
Memory trick: DLP: Don't Let PII Leak!