Certified Cloud Security Professional (CCSP) flashcards
160 free flashcards. Tap a card to flip it.
PaaS (Platform as a Service)
Flip cardA cloud service model where the provider delivers a computing platform and solution stack, allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure.
- Provider manages OS, middleware, runtime.
- Customer manages applications and data.
- Focus on application development and deployment.
Memory trick: I-P-S: Infrastructure, Platform, Software – Increasing abstraction, decreasing control.
Cryptographic Erasure
Flip cardA data destruction method that renders encrypted data permanently unrecoverable by destroying or revoking access to the encryption keys. The underlying encrypted data may persist, but it becomes unintelligible and unusable without the key.
- Key destruction/revocation.
- Encrypted data becomes unrecoverable.
- Ideal for virtualized and cloud environments.
Memory trick: Keys Erased, Cloud Data Cleared.
Cloud Object Lock
Flip cardA feature in cloud object storage that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, ensuring data immutability.
- Provides Write-Once-Read-Many (WORM) capability.
- Protects against accidental or malicious deletion/modification.
- Can be configured with retention periods or legal holds.
Memory trick: LOCK your precious data in the cloud, so it stays exactly as you made it, safe from any slip-ups or bad actors.
Hardware Security Module (HSM) as a Service
Flip cardHSM as a Service is a cloud offering that provides dedicated, FIPS 140-2 certified hardware for cryptographic key generation, storage, and operations, ensuring a high level of security and regulatory compliance for key management.
- Provides dedicated, tamper-resistant hardware.
- Often FIPS 140-2 Level 3 certified.
- Keys are generated and stored within the HSM, never leaving it.
- Offers high assurance for critical cryptographic operations.
Memory trick: HSM: Hardware Security Meets Maximum Assurance.
Container Image Scanning
Flip cardThe automated process of analyzing container images for known vulnerabilities, misconfigurations, and policy violations, typically integrated into CI/CD pipelines.
- Identifies security risks before containers are deployed.
- Leverages vulnerability databases (CVEs).
- Helps enforce security policies and compliance standards.
Memory trick: Before you put your container on the boat (registry) and sail it (deploy), SCAN it for holes! Make sure it's seaworthy and won't sink your operations.
Data Discovery
Flip cardThe process of identifying, locating, and mapping sensitive data across an organization's IT environment, including structured and unstructured data stores, to understand its prevalence and ensure proper protection.
- Identifies sensitive data locations.
- Works across structured and unstructured data.
- Crucial first step for data protection initiatives.
- Helps with compliance and risk assessment.
Memory trick: Discovery is like finding hidden treasure before you move the map.
Cloud Audit Logging
Flip cardA cloud service feature that records API calls and administrative actions for all resources, providing an immutable audit trail for security and compliance.
- Records all management plane activities.
- Logs are typically immutable and time-stamped.
- Essential for compliance, forensics, and security monitoring.
Memory trick: Audit logs record every cloud command, for compliance always at hand.
Multi-Region Active-Active DR
Flip cardA disaster recovery strategy where an application is fully deployed and active in multiple, geographically separate cloud regions, processing requests concurrently.
- Provides highest availability and lowest RTO/RPO.
- Routes traffic automatically to active regions upon failure.
- More complex and expensive to implement.
Memory trick: Always Active, Always Available, Across All Areas.
Cloud Access Security Broker (CASB)
Flip cardA security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed. CASBs provide visibility, compliance, data security, and threat protection.
- Intermediary between users and cloud services.
- Provides visibility, compliance, data security, threat protection.
- Enforces policies in real-time across multiple cloud services.
Memory trick: CASB: Control Access, Secure Behavior.
Community Cloud
Flip cardA cloud infrastructure shared by several organizations with shared concerns (e.g., mission, security requirements, policy, and compliance considerations).
- Shared by specific, related organizations.
- Addresses common regulatory or security needs.
- Can be managed internally or by a third party.
Memory trick: PUblic, PRIvate, HYbrid, COmmunity: Pick the right cloud for your crowd.
Private Cloud
Flip cardA cloud deployment model where the cloud infrastructure is provisioned for exclusive use by a single organization.
- Offers exclusive control over infrastructure
- Can be managed internally or by a third party
- Typically used for sensitive data and high compliance needs
Memory trick: Private clouds prioritize personal control.
Encryption at Rest
Flip cardThe practice of encrypting data when it is stored on a physical storage device, such as a hard drive, solid-state drive, or cloud storage bucket.
- Protects data from unauthorized access even if the storage medium is compromised.
- Can be managed by the customer (client-side) or the cloud provider (server-side).
- Crucial for data confidentiality and compliance requirements.
Memory trick: Encryption at rest is like locking your diary even if someone breaks into your room.
Data Classification
Flip cardThe process of organizing data into categories based on its sensitivity, value, and regulatory requirements, which then informs the application of appropriate security controls and policies.
- Categorizes data based on sensitivity and value.
- Informs security controls (encryption, access).
- Drives retention and disposal policies.
- Crucial for compliance and risk management.
Memory trick: Classification is labeling the data to know how to treat it.
Fault Tolerance
Flip cardThe property that enables a system to continue operating properly in the event of the failure of some of its components.
- Achieved through redundancy and automatic failover mechanisms.
- Crucial for high availability and business continuity.
- Often involves deploying across multiple availability zones or regions.
Memory trick: Fault tolerance is like having spare tires for your car, so a flat doesn't stop your journey.
Virtualization Escape
Flip cardA security vulnerability or exploit that allows an attacker to break out of a guest virtual machine and gain unauthorized access to the host operating system (hypervisor) or other virtual machines running on the same host.
- Considered a highly severe threat in virtualized environments.
- Can compromise the isolation between virtual machines.
- Requires robust hypervisor security and patching.
Memory trick: Virtualization Escape: The VM is a 'cage', and the attacker 'escapes' it.
Data Replication
Flip cardThe process of continuously copying data from one location to another, maintaining an up-to-date duplicate, primarily for disaster recovery, high availability, and load balancing.
- Continuous data copying.
- Aims for low RPO (Recovery Point Objective).
- Supports disaster recovery and business continuity.
- Can be synchronous or asynchronous.
Memory trick: Replication is like having a twin, always up-to-date and ready.
Security Groups/NACLs
Flip cardCloud-native virtual firewall services that control inbound and outbound network traffic for virtual machines or subnets based on rules.
- Filter traffic based on IP, port, protocol.
- Act as a virtual firewall.
- Configurable at VM or subnet level.
Memory trick: NAC and Security Groups act as traffic cops for your cloud VMs.
Measured Service
Flip cardA characteristic of cloud computing where resource usage is monitored, controlled, and reported, providing transparency for both the provider and consumer.
- Enables 'pay-as-you-go' or 'pay-per-use' billing models.
- Allows consumers to track and optimize their resource consumption.
- Often includes metrics like compute time, data transfer, and storage used.
Memory trick: Measured Service: The cloud is 'metered' like your utility bill.
Cloud VM Memory Forensics
Flip cardThe process of capturing and analyzing the volatile memory (RAM) of a virtual machine in a cloud environment to investigate security incidents and potential compromises.
- Captures runtime state, processes, network connections, and hidden data.
- Essential for detecting advanced persistent threats (APTs) and malware.
- Requires specific cloud provider capabilities or third-party tools.
Memory trick: Memory holds the secrets of the moment.
Cryptographic Hashing
Flip cardCryptographic hashing is a mathematical algorithm that maps data of arbitrary size to a fixed-size bit array (hash value or message digest). It is primarily used for ensuring data integrity, as any alteration to the input data will produce a different hash value.
- Generates a fixed-size output (hash value).
- One-way function (computationally infeasible to reverse).
- Collision resistant (hard to find two inputs with same hash).
- Primarily used for data integrity verification.
Memory trick: Hash: Integrity's Hidden Helper.
Confidential Computing
Flip cardA cloud security technology that protects data in use by performing computation in a hardware-based Trusted Execution Environment (TEE), shielding it from unauthorized access even from the cloud provider.
- Protects data during processing (in use).
- Utilizes hardware-based Trusted Execution Environments (TEEs).
- Shields data from hypervisor, OS, and cloud administrator access.
Memory trick: At Rest, In Transit, In Use: Data needs protection in every phase.
Data Masking
Flip cardA technique that replaces sensitive data with fictitious but realistic data, preserving the data's format and referential integrity, primarily used for non-production environments like development, testing, and training.
- Replaces real data with fake, but realistic, data.
- Preserves data format and referential integrity.
- Used in non-production environments (dev, test, training).
- Can be static (one-time) or dynamic (on-the-fly).
Memory trick: Masking puts on a fake face, keeping the structure intact for testing.
Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)
Flip cardA server-side encryption option where the cloud provider's Key Management Service (KMS) generates and manages the encryption keys, while allowing the customer to control key usage and revocation policies.
- Cloud provider generates and manages keys.
- Customer retains policy control over key usage and revocation.
- Often integrated with other cloud services.
Memory trick: Keys Managed Safely, Customer Retains Control
Physical Data Isolation
Flip cardEnsuring that one tenant's data resides on distinct physical hardware resources, preventing any sharing of underlying physical storage with other tenants.
- Achieved through dedicated hardware (disks, servers).
- Provides strongest form of isolation.
- More expensive and less common in multi-tenant cloud.
Memory trick: Physical disks for each tenant, like private vaults, no sharing meant.
Serverless Ephemeral Compute
Flip cardIn serverless computing, compute environments are short-lived, created for each function invocation and then destroyed, providing isolation and automatic resource management.
- Each function execution runs in a new, isolated container/environment.
- Resources are automatically provisioned and de-provisioned.
- Contributes to security by preventing state leakage between invocations.
Memory trick: Serverless is like a pop-up shop for code: it appears, does its job, and disappears. EPHEMERAL COMPUTE means it's a new shop every time, keeping things clean and separate.
Least Privilege (Serverless)
Flip cardApplying the principle of least privilege to serverless functions, granting them only the minimum necessary permissions to perform their specific tasks, thereby reducing the attack surface.
- Minimizes the blast radius of a compromised function.
- Requires careful IAM policy definition for each function.
- Challenges include dynamic permissions and multiple service integrations.
Memory trick: Only give the function what it absolutely needs to do its job.
NIST Cloud Characteristics
Flip cardThe essential features that define a cloud computing environment, as outlined by NIST.
- On-demand self-service: Users can provision resources without human interaction.
- Broad network access: Services are available over the network via standard mechanisms.
- Resource pooling: Provider's computing resources are pooled to serve multiple consumers.
- Rapid elasticity: Capabilities can be rapidly and elastically provisioned and released.
Memory trick: On-demand, Broad, Pooled, Elastic, Measured: Every cloud has these features.
Client-Side Encryption with Customer-Managed Keys (CSEK)
Flip cardA data encryption method where data is encrypted by the customer's system before being uploaded to the cloud, and the encryption keys are generated and retained exclusively by the customer.
- Data encrypted pre-upload.
- Customer retains full control of encryption keys.
- Cloud provider never sees unencrypted data or keys.
- Provides highest level of data confidentiality and key isolation.
Memory trick: Keys in hand, data secure, out of provider's view.
Regional Cloud Storage
Flip cardA cloud storage configuration where data is stored and replicated exclusively within a single, specified geographic region, ensuring data residency.
- Guarantees data remains within a defined geographical boundary.
- Important for compliance with data residency laws (e.g., GDPR, CCPA).
- Offers high availability within the region, but not across regions.
Memory trick: Data residency is about where your data 'lives'. If it HAS to stay in one specific house, you choose a REGIONAL storage plan, not one that lets it travel.
Secure Defaults
Flip cardA security design principle advocating that systems and services should be configured with the most secure settings by default, requiring explicit action to reduce security.
- Minimizes misconfiguration risks
- Reduces attack surface out-of-the-box
- Enhances overall system security posture
Memory trick: Secure defaults set you up for success.
Cloud Security Posture Management (CSPM)
Flip cardA category of security tools that continuously monitor and assess the security posture of cloud environments by identifying misconfigurations, policy violations, and compliance risks.
- Focuses on the cloud control/management plane.
- Detects misconfigurations in IaaS, PaaS, and SaaS services.
- Often provides automated remediation suggestions or actions.
Memory trick: Securing the COMMAND CENTER (management plane) needs a constant WATCHDOG. CSPM is like having a vigilant guard always checking the locks and rules, not just looking at security footage (SIEM) afterward.
Searchable Encryption
Flip cardSearchable encryption is a cryptographic technique that allows users to perform keyword searches over encrypted data without decrypting the data first. This enables secure querying and analysis of sensitive information stored in untrusted environments.
- Enables searching on ciphertext.
- Data remains encrypted during search operations.
- Useful for cloud-based data analytics and retrieval.
- Can be symmetric or asymmetric based.
Memory trick: Searchable: Seek Silently, Securely.
Field-Level Encryption
Flip cardA data protection technique where specific sensitive fields within a database or application are individually encrypted, rather than encrypting the entire database or data set. This allows for granular protection and control over sensitive elements.
- Encrypts individual database fields.
- Granular control over sensitive data.
- Prevents cleartext exposure in logs/storage.
Memory trick: Fields Encrypted, Logs are Clean.
Customer-Controlled Keys (CCK)
Flip cardCustomer-Controlled Keys (CCK) refers to a key management model where the customer generates, stores, and manages their encryption keys entirely outside the cloud provider's infrastructure, typically using an on-premises or third-party external Hardware Security Module (HSM).
- Keys are never exposed to the cloud provider.
- Customer retains full control over key lifecycle.
- Often involves an external HSM for key generation and storage.
- Cloud services request key operations from the external HSM.
Memory trick: CCK: Customer's Complete Key Control.
Key Management
Flip cardThe process of managing cryptographic keys throughout their lifecycle, including generation, storage, distribution, usage, and revocation.
- Crucial for data encryption effectiveness
- Can be complex in cloud environments
- Often involves HSMs for enhanced security
Memory trick: Key challenges in the cloud require careful handling.
Shared Technology Vulnerabilities
Flip cardSecurity challenges arising from shared underlying cloud infrastructure components (e.g., hypervisors, network devices), where a vulnerability can affect multiple tenants.
- Includes hypervisor escape, shared memory attacks
- Requires strong patching and configuration management by CSP
- A key concern in multi-tenant environments
Memory trick: Shared tech, shared risk.
Cloud Private Connectivity
Flip cardDedicated network services (e.g., Direct Connect, ExpressRoute) that establish a private, high-bandwidth, low-latency connection between on-premises environments and cloud VPCs, bypassing the public internet.
- Bypasses public internet for enhanced security and performance.
- Provides consistent network performance.
- Essential for hybrid cloud architectures requiring secure, fast links.
Memory trick: Direct routes are always the fastest routes.
Measured Boot (Virtualization)
Flip cardA security feature that uses a hardware root of trust (like a TPM) to measure and record the integrity of boot components and the OS kernel, verifying no tampering has occurred.
- Verifies integrity before the OS fully loads.
- Creates a cryptographic 'report' of the boot process.
- Protects against bootkits and rootkits.
Memory trick: Ensuring a VM's boot is clean is like having a bouncer check every guest's ID at the door. MEASURED BOOT, with a TPM, is that super strict bouncer making sure no one sneaks in.
Tokenization
Flip cardA data security technique that replaces sensitive data with a unique, non-sensitive identifier (token) that has no extrinsic meaning or exploitable value, while the original data is stored securely elsewhere.
- Replaces sensitive data with a token.
- Original data is stored in a secure token vault.
- Original data can be retrieved from the token.
- Commonly used for credit card numbers and PII.
Memory trick: Masks hide, tokens replace, hashes seal, anonymize deletes.
Data Retention
Flip cardA policy that defines the period for which specific types of data must be kept and specifies the procedures for their secure disposal once that period expires, driven by legal, regulatory, or business requirements.
- Defines how long data must be kept.
- Specifies secure disposal methods.
- Driven by compliance and legal needs.
- Part of a broader data lifecycle management strategy.
Memory trick: Retention sets the timer for data's life and death.
Serverless Security Controls
Flip cardSpecific security practices tailored to protect serverless functions and applications from common threats.
- Code scanning to prevent injection.
- Least privilege IAM for function roles.
- Input validation is crucial.
Memory trick: Scan the code and grant least privilege, for serverless safety you must give.
Homomorphic Encryption
Flip cardHomomorphic encryption is a form of encryption that allows computations to be performed on ciphertext, generating an encrypted result which, when decrypted, matches the result of operations performed on the plaintext.
- Enables computation on encrypted data.
- Maintains data confidentiality throughout its lifecycle, even during processing.
- Computation results remain encrypted.
- Comes in partially, somewhat, and fully homomorphic forms.
Memory trick: Homomorphic Heroes Compute Encrypted.
Archive Storage
Flip cardA cloud storage class optimized for extremely infrequent data access and long-term retention, offering the lowest storage costs but typically involving higher retrieval latency (hours to days) and retrieval fees.
- Lowest storage costs.
- Highest retrieval latency (hours to days).
- Ideal for regulatory compliance and backups with long retention.
Memory trick: Archive is for Ages, Access is Awaited.
Pseudonymization
Flip cardThe process of replacing sensitive identifiers within a dataset with artificial identifiers or pseudonyms, making it difficult to directly identify individuals without additional information.
- Enhances data privacy while maintaining data utility for analysis.
- Reversible with the right key or additional information.
- A common technique to comply with privacy regulations like GDPR.
Memory trick: Privacy shields data, but analysis still needs to see the patterns.
Cloud API Activity Logs
Flip cardLogs that capture all API calls and administrative actions made to a cloud provider's management plane, providing an audit trail for security and operational purposes.
- Records 'who, what, when, where' for management plane actions.
- Crucial for security investigations and compliance.
- Examples: AWS CloudTrail, Azure Activity Logs, GCP Cloud Audit Logs.
Memory trick: API logs capture every cloud command, clear evidence for the investigation at hand.
Information Rights Management (IRM)
Flip cardInformation Rights Management (IRM) is a subset of Digital Rights Management (DRM) focused on applying persistent protection to sensitive documents and emails, controlling who can access, modify, print, forward, or screenshot the content, even after it leaves the organization's network.
- Applies persistent usage policies to documents.
- Controls access and actions (print, edit, share) on content.
- Protection remains even when offline or outside the network.
- Often integrated with document management systems.
Memory trick: IRM: Information Rights Maintain Control.
Multi-tenancy
Flip cardAn architecture where a single instance of a software application or system serves multiple customers (tenants), each tenant's data and configurations being isolated and invisible to other tenants.
- Core concept of public cloud efficiency.
- Requires robust logical separation mechanisms.
- Optimizes resource utilization across customers.
Memory trick: Multi-tenancy: Many tenants, one building, separate apartments.
HSM as a Service
Flip cardA cloud service that provides dedicated, FIPS-validated Hardware Security Modules (HSMs) for customer-exclusive use, offering the highest level of control over encryption keys.
- Provides dedicated hardware for key generation and storage.
- Offers cryptographic isolation and tamper resistance.
- Meets strict compliance requirements for key control.
Memory trick: When it comes to your most precious keys, do you trust the hotel safe (CMK), or do you want your own personal, Fort Knox-level vault (HSM)? For 'full control', you need your own vault.
Platform as a Service (PaaS)
Flip cardA cloud service model that provides a complete development and deployment environment in the cloud, with all the resources required to build, run, and manage applications.
- Abstracts away infrastructure, OS, and runtime
- Focuses on application development and deployment
- Managed by the cloud provider
Memory trick: IaaS, PaaS, SaaS - I Prefer Serverless Solutions.
Hardware-Enforced Virtualization
Flip cardA virtualization technique that uses specific CPU features (e.g., Intel VT-x, AMD-V) to assist the hypervisor in managing virtual machines, providing stronger isolation and better performance.
- Leverages CPU extensions for efficient virtualization.
- Provides strong isolation between virtual machines.
- Enhances security by separating guest OS environments.
Memory trick: Hardware hypervisors keep secrets hidden, like a vault of isolated divisions.
Block Storage
Flip cardBlock storage is a type of data storage that stores data in fixed-size blocks, each with a unique address, allowing operating systems to treat them as raw hard drives. It offers high performance and low latency, making it ideal for databases, virtual machines, and transactional workloads.
- Provides raw storage volumes.
- Accessed at the block level, like a physical disk.
- Offers high performance and low latency.
- Suitable for databases, OS volumes, and transactional applications.
Memory trick: Block Storage: Building Blocks for Performance.
Active-Active Replication
Flip cardActive-active replication is a high-availability and disaster recovery strategy where multiple instances of an application and its underlying data are simultaneously running and processing requests across different geographical regions or data centers, ensuring continuous operation with near-zero RTO and RPO.
- All instances are live and serving traffic.
- Data is synchronized in real-time across instances.
- Provides near-zero RTO and RPO.
- Complex to implement and manage consistency.
Memory trick: Active-Active: Always On, Always Ready.
Least Privilege
Flip cardA security principle that requires that an individual or process be granted only the minimum necessary access rights or permissions to perform its job function, and no more.
- Reduces the attack surface.
- Limits the impact of a compromise.
- Applies to users, processes, services, and applications.
Memory trick: CIA Triad and beyond: Confidentiality, Integrity, Availability, plus these key design rules.
Serverless Security Challenges
Flip cardSecurity considerations specific to serverless computing, where the cloud provider manages servers and infrastructure, shifting customer focus to application-level security.
- Focus on function code security, API gateway protection, and IAM.
- Reduced visibility into underlying infrastructure.
- Increased attack surface through numerous, often small, functions and event triggers.
Memory trick: Serverless security: The provider handles the 'house', you secure the 'doors' (APIs) and 'contents' (functions).
Cloud Management Plane Security
Flip cardSecuring the control plane or management interface of a cloud environment, which allows users to provision, configure, and manage cloud resources.
- Relies heavily on Identity and Access Management (IAM).
- Requires strong authentication, authorization, and auditing.
- API security is paramount as most interactions are programmatic.
Memory trick: Roles for tools, no root rules.
Cloud IP Spoofing Protection
Flip cardA cloud network security feature that prevents a virtual machine from sending or receiving network traffic with an IP address that is not legitimately assigned to its network interface.
- Protects against unauthorized use of IP addresses.
- Typically configured at the virtual network interface level.
- Enhances network integrity and prevents impersonation.
Memory trick: To stop network pretenders (spoofing), you need a strict ID check. IP SPOOFING PROTECTION acts like a bouncer at the network interface, only allowing traffic with the correct, assigned ID.
Rapid Elasticity
Flip cardThe ability of cloud computing resources to be scaled up or down quickly and automatically to meet varying demand.
- Enables dynamic resource allocation
- Supports sudden workload changes
- A key benefit for cost optimization and performance
Memory trick: REMOS: Rapidly Elastic Measured On-demand Self-service Resource Pooling Broad Network Access.
Warm Standby DR
Flip cardA disaster recovery strategy where a scaled-down but functional copy of the primary environment is maintained in a secondary location with continuous data replication.
- Lower RTO/RPO than backup & restore or pilot light.
- Higher cost than pilot light due to running resources.
- Requires continuous synchronization of data.
Memory trick: For quick recovery, keep it warm and ready, so your systems stay steady.
File Storage
Flip cardA cloud storage type that provides shared file system access over standard protocols (like NFS or SMB), allowing multiple virtual machines or users to access and share files with hierarchical directory structures and file-level permissions.
- Shared access via NFS/SMB.
- Hierarchical directory structure.
- Supports file-level permissions.
Memory trick: Files for Shares, Blocks for Boot, Objects for Buckets.
IaaS (Infrastructure as a Service)
Flip cardA cloud service model that provides virtualized computing resources over the internet, including virtual machines, storage, and networks.
- Highest level of control for the customer (OS, middleware, applications).
- Provider manages virtualization, servers, storage, networking.
- Examples: AWS EC2, Azure VMs, Google Compute Engine.
Memory trick: I-P-S: Infrastructure, Platform, Software – Increasing abstraction, decreasing control.