Certified Cloud Security Professional (CCSP) flashcards
160 free flashcards. Tap a card to flip it.
Format-Preserving Encryption (FPE)
Flip cardA type of encryption that transforms plaintext into ciphertext of the same format and length as the original plaintext. This is particularly useful for protecting sensitive data in databases or applications that rely on specific data formats and lengths.
- Ciphertext retains original data format and length.
- Useful for legacy systems and databases.
- Allows applications to function without modification when sensitive data is encrypted.
Memory trick: FPE Preserves Form, Protects Privacy.
Shared Responsibility Model
Flip cardA framework outlining security responsibilities between a cloud provider and its customers, differentiating between 'security of the cloud' and 'security in the cloud'.
- CSP: 'Security OF the cloud' (physical, hypervisor).
- Customer: 'Security IN the cloud' (OS, apps, data, config).
- Responsibility varies by service model (IaaS, PaaS, SaaS).
Memory trick: CSP secures the cloud beneath, customer handles all within.
Cloud-Agnostic Security
Flip cardA security approach or set of tools designed to operate uniformly across multiple cloud providers, reducing vendor lock-in and simplifying management in multi-cloud environments.
- Enables consistent policy enforcement and visibility.
- Reduces operational complexity in multi-cloud deployments.
- Often leverages open standards or provides abstraction layers.
Memory trick: Cloud-agnostic security is like a universal remote for all your cloud TVs.
Block Storage Latency
Flip cardBlock storage delivers the lowest latency among common cloud storage types because it provides raw, direct access to storage volumes, allowing operating systems and applications to manage data at a granular level, similar to a physical hard drive.
- Offers raw disk access.
- Key for low-latency, high-performance applications.
- Ideal for databases and boot volumes.
- Often implemented with SSDs for maximum speed.
Memory trick: Block is Best for Blazing Speed.
Bare-Metal Isolation
Flip cardA form of isolation in cloud computing where a single tenant is allocated dedicated physical hardware resources, with no virtualization layer or shared hardware.
- Provides strongest physical and logical separation
- Eliminates hypervisor-based vulnerabilities (virtualization escape)
- Highest cost, typically used for extremely sensitive workloads
Memory trick: Bare metal means *only* your metal.
Cloud Regional Storage
Flip cardCloud storage solutions designed to keep data physically located and processed within specific geographic regions or countries, to comply with data residency regulations.
- Ensures data stays within geopolitical boundaries.
- Crucial for compliance with GDPR, CCPA, and other local laws.
- Impacts latency and availability depending on user location.
Memory trick: Data stays, where the country says.
Network Segmentation (Micro-segmentation)
Flip cardThe practice of dividing a network into smaller, isolated segments to limit lateral movement of threats and reduce the attack surface.
- Crucial for limiting blast radius in cloud environments
- Implemented using Security Groups, NACLs, or firewalls
- Enhances zero-trust architecture principles
Memory trick: Segment your network, stop the spread.
Infrastructure as a Service (IaaS)
Flip cardA cloud service model where a provider offers virtualized computing resources over the internet, including virtual machines, storage, networks, and operating systems.
- Customers manage operating systems, applications, and data.
- High degree of control over the infrastructure.
- Provider manages the underlying physical infrastructure.
Memory trick: IaaS is like building your own house on rented land, PaaS is an apartment, and SaaS is a hotel room.
Geographical Distribution (Data Residency)
Flip cardThe physical location where data is stored and processed within a cloud environment, often dictated by legal or regulatory requirements (data residency).
- Crucial for compliance with data protection laws (e.g., GDPR, CCPA).
- Impacts latency, disaster recovery, and international data transfer regulations.
- Cloud providers offer regional and availability zone options to address this.
Memory trick: Geographical distribution is like knowing where your 'cloud' actually 'rains' data.
Data Locality (Data Residency)
Flip cardThe principle that data should be stored and processed within a specific geographic location or jurisdiction, often driven by legal or regulatory requirements.
- Crucial for compliance with data privacy laws (GDPR, HIPAA)
- Impacts cloud region selection and architecture
- Can affect disaster recovery and backup strategies
Memory trick: Data resides where the law decides.
Digital Rights Management (DRM)
Flip cardA set of technologies used to control access to and usage of copyrighted material and proprietary content, often by embedding usage rules directly into the digital assets themselves.
- Enforces usage policies on digital content.
- Provides persistent protection regardless of location.
- Controls actions like viewing, editing, printing, copying, sharing.
- Requires client-side enforcement mechanisms.
Memory trick: DRM locks the document, even after it leaves your hands.
Archival Cloud Storage
Flip cardA cloud storage class optimized for very long-term retention of data that is accessed extremely infrequently, offering the lowest storage costs but with the highest retrieval latency (often hours to days).
- Lowest cost per GB.
- Highest retrieval latency (hours to days).
- Designed for long-term retention and compliance.
- Suitable for rarely accessed, non-critical data.
Memory trick: Hot for quick, Cold for slow, Archive for forever and cheap.
Cloud Dedicated Hosts
Flip cardA cloud offering that provides physical servers dedicated for your exclusive use, addressing concerns about multi-tenancy on the underlying hardware.
- Ensures physical isolation from other cloud tenants.
- Can help meet specific compliance requirements.
- Often more expensive than shared instances.
Memory trick: When you need your own space, get a DEDICATED HOST, so no one else can SHARE your physical server. Think of it as a private room in a shared hotel.
Database-as-a-Service (DBaaS)
Flip cardDatabase-as-a-Service (DBaaS) is a cloud computing service model that provides customers with access to a database without the need for setting up, configuring, or managing the underlying hardware or software.
- Cloud provider manages database infrastructure and software.
- Offers scalability, high availability, and often built-in backups.
- Supports various database types (SQL, NoSQL).
- Commonly used for multi-tenant applications with logical isolation.
Memory trick: DBaaS: Database Best Available as a Service.
Continuous Data Protection (CDP)
Flip cardA backup and recovery strategy that continuously captures or tracks data changes, allowing a user to restore data to any point in time. This approach typically offers very low Recovery Point Objectives (RPO) and fast Recovery Time Objectives (RTO).
- Captures changes continuously.
- Enables recovery to any point in time.
- Achieves near-zero RPO and low RTO.
Memory trick: CDP: Constantly Data Protected, Critically Quick Recovery.
Cloud IP Spoofing Protection
Flip cardA cloud network security feature (e.g., Source/Destination Check) that prevents virtual machines or network interfaces from sending or receiving traffic with forged source or destination IP addresses.
- Ensures network traffic originates from and is destined for legitimate IPs.
- Protects against man-in-the-middle and unauthorized access attempts.
- Often a default setting on cloud network interfaces.
Memory trick: Spoofing stopped, source confirmed.
Key Separation
Flip cardA cryptographic key management principle stating that different keys should be used for different purposes (e.g., encryption, signing) or for different data sets/tenants. This limits the impact of a single key compromise.
- Unique keys for different purposes or data.
- Limits impact of a key compromise.
- Crucial for multi-tenant environments.
Memory trick: Separate Keys, Secure Silos.
Rapid Elasticity
Flip cardThe ability of cloud computing resources to be quickly and automatically scaled up or down to meet fluctuating demand.
- Handles unpredictable workloads.
- Optimizes resource utilization.
- Reduces costs by avoiding over-provisioning.
Memory trick: On-demand, Broad, Pooled, Elastic, Measured: Every cloud has these features.
IaaS (Infrastructure as a Service)
Flip cardA cloud service model that provides virtualized computing resources over the internet, including virtual machines, storage, and networks.
- Highest level of control for the customer (OS, middleware, applications).
- Provider manages virtualization, servers, storage, networking.
- Examples: AWS EC2, Azure VMs, Google Compute Engine.
Memory trick: I-P-S: Infrastructure, Platform, Software – Increasing abstraction, decreasing control.
File Storage
Flip cardA cloud storage type that provides shared file system access over standard protocols (like NFS or SMB), allowing multiple virtual machines or users to access and share files with hierarchical directory structures and file-level permissions.
- Shared access via NFS/SMB.
- Hierarchical directory structure.
- Supports file-level permissions.
Memory trick: Files for Shares, Blocks for Boot, Objects for Buckets.
Warm Standby DR
Flip cardA disaster recovery strategy where a scaled-down but functional copy of the primary environment is maintained in a secondary location with continuous data replication.
- Lower RTO/RPO than backup & restore or pilot light.
- Higher cost than pilot light due to running resources.
- Requires continuous synchronization of data.
Memory trick: For quick recovery, keep it warm and ready, so your systems stay steady.
Synchronous Replication
Flip cardA data replication strategy where data is written to both the primary and secondary locations simultaneously, and the write operation is not considered complete until both writes are confirmed. This ensures high data consistency and zero data loss in case of a primary failure.
- Writes to primary and secondary simultaneously.
- Acknowledges write only after both locations confirm.
- Ensures high consistency and zero RPO (Recovery Point Objective).
Memory trick: Sync for Safety, Async for Speed.
Cloud Interoperability and Portability
Flip cardThe ability of cloud systems to work together and the ease with which data and applications can be moved between different cloud environments or between on-premises and cloud.
- Lack of interoperability can lead to vendor lock-in.
- Challenges arise from proprietary APIs, data formats, and infrastructure dependencies.
- Standards and open-source technologies aim to improve both.
Memory trick: Interoperability and Portability: Can your 'app-boat' sail between different 'cloud-seas'?
Cloud-Agnostic Architecture
Flip cardA design philosophy that aims to create cloud applications and services that can run on any cloud provider's infrastructure with minimal or no changes.
- Reduces vendor lock-in
- Increases portability and flexibility
- Often relies on open standards and containerization
Memory trick: Secure clouds are Agnostic, Encrypted, and Audited.
Multi-party Computation (MPC)
Flip cardA cryptographic technique that allows multiple parties to jointly compute a function over their private inputs while keeping those inputs secret from each other.
- Ensures data privacy even when processed by untrusted entities.
- Prevents any single party from gaining full knowledge of the data.
- Useful for collaborative analysis of sensitive data without revealing individual contributions.
Memory trick: MPC is like a secret ballot election: everyone contributes their vote, but no one sees individual choices.
Container Security Best Practices
Flip cardA set of practices to secure containerized applications throughout their lifecycle, from image creation to runtime execution.
- Scan images for vulnerabilities pre-deployment.
- Enforce runtime policies for container behavior.
- Use minimal base images.
Memory trick: Scan your boxes before they run, then watch them closely under the sun.
Data Lifecycle Management (DLM)
Flip cardA comprehensive approach to managing data from its creation to its eventual destruction, ensuring appropriate protection, availability, and integrity at every stage.
- Covers data in all states: at rest, in transit, in use.
- Includes policies for creation, storage, use, sharing, archiving, and destruction.
- Essential for consistent security and compliance for sensitive data.
Memory trick: From birth to dust, the data lifecycle provides trust.
CSA Data Breach Accountability
Flip cardAccountability for data breaches in Cloud Service Agreements (CSAs) is primarily defined in the Data Processing Addendum (DPA) and specific incident response clauses, which detail the responsibilities, notification requirements, investigation, and remediation obligations of the cloud provider.
- DPA defines data protection roles and responsibilities.
- Incident response clauses specify breach handling.
- Crucial for legal and regulatory compliance (e.g., GDPR, HIPAA).
Memory trick: DPA and incident clauses define who pays when data breaks.
Vendor Lock-in
Flip cardVendor lock-in refers to a situation where a customer is dependent on a single vendor for products and services and cannot switch to another vendor without substantial costs, effort, or business disruption.
- Often due to proprietary technologies or complex integrations.
- Limits flexibility and negotiation power.
- Mitigated by open standards, APIs, and multi-cloud strategies.
Memory trick: Trapped in the cloud? Portability is your escape key.
Cost-Effective Cloud Compliance
Flip cardCost-effective cloud compliance for startups or organizations with limited budgets often involves leveraging existing cloud provider certifications and shared responsibility models, focusing on essential controls, and utilizing open-source or simpler tools before investing in complex solutions.
- Start with provider's existing compliance artifacts.
- Understand the Shared Responsibility Model.
- Prioritize critical regulations and controls.
Memory trick: Startups save compliance cash by using the cloud provider's documents.
End-to-End Encryption in Multi-Cloud Transit
Flip cardThe practice of encrypting data at its source and decrypting it only at its final destination, ensuring protection across multiple network segments and diverse cloud environments.
- Protects data regardless of intervening networks or services.
- Requires robust key management across all involved parties.
- Critical for sensitive data moving between hybrid and multi-cloud.
Memory trick: Data in transit, diverse paths; end-to-end encrypt, or risk the wrath.
External Audit Purpose
Flip cardThe primary purpose of an external audit in a cloud environment is to provide an independent, objective assessment of an organization's security posture, control effectiveness, and compliance with specific regulations, standards, or contractual obligations.
- Performed by independent third parties.
- Verifies compliance with standards (e.g., ISO 27001, SOC 2).
- Assesses effectiveness of implemented controls.
Memory trick: Audits verify, they don't develop or teach.
Sub-Processor Risk
Flip cardRisks arising from third-party entities engaged by a cloud service provider to process customer data, where the customer lacks direct contractual control or visibility.
- Customer is ultimately responsible for data protection.
- Sub-processors may not meet required security/compliance standards.
- Requires robust due diligence and contractual flow-down clauses.
Memory trick: Sub-processors are hidden links; without oversight, compliance sinks.
Principle of Least Privilege
Flip cardThe Principle of Least Privilege (PoLP) is a security concept that ensures users, programs, or processes are granted only the minimum necessary rights or permissions to perform their authorized functions, thereby limiting the potential damage from errors or malicious actions.
- Grants minimum necessary access.
- Reduces attack surface.
- Limits impact of security breaches or errors.
Memory trick: Minimum keys mean minimum damage if they're lost.
GDPR Data Breach Notification
Flip cardThe legal requirement under GDPR for data controllers to notify supervisory authorities and, in some cases, affected individuals, of personal data breaches within specific timelines.
- Notification to supervisory authority within 72 hours (if feasible).
- Notification to data subjects if high risk to their rights/freedoms.
- Applies to data controllers, even if breach occurs at processor.
Memory trick: GDPR breach: 72 hours, notify the authority, no undue delays.
Cloud GRC Framework
Flip cardA Cloud Governance, Risk, and Compliance (GRC) framework is a structured approach that integrates an organization's governance, enterprise risk management, and regulatory compliance activities, specifically adapted for cloud computing environments, to achieve objectives, address uncertainties, and act with integrity.
- Integrates governance, risk, and compliance activities.
- Crucial for complex regulatory environments (e.g., multi-jurisdictional).
- Ensures continuous adherence to policies and regulations.
Memory trick: GRC is the engine for continuous cloud compliance.
Cloud Service Agreement Risks
Flip cardCloud Service Agreements (CSAs) contain clauses that can introduce significant risks for customers, particularly those related to service availability, data access, and provider liability, which must be carefully reviewed and negotiated.
- Defines responsibilities and liabilities of both parties.
- Termination clauses can pose significant business continuity risks.
- Data privacy and ownership are critical aspects to review.
Memory trick: Termination without notice means your business stops, fast.
Leveraging CSP-Native Compliance
Flip cardA strategy where cloud customers utilize the built-in security features, compliance certifications, and shared responsibility model of their Cloud Service Provider to meet their own regulatory and security obligations.
- Cost-effective for startups and smaller organizations.
- Relies on CSP's continuous investment in security.
- Requires understanding the shared responsibility model.
Memory trick: For lean compliance, CSP-native features are the effective alliance.
Cloud Supply Chain Risk
Flip cardCloud Supply Chain Risk refers to the risks introduced to an organization's operations, data, and security posture due to its reliance on external cloud service providers and their sub-processors, particularly concerning their security practices, transparency, and incident response capabilities.
- Involves risks from third-party dependencies.
- Lack of transparency from vendors is a key indicator.
- Impacts overall security and compliance posture.
Memory trick: Hidden cloud practices mean a risky supply chain.
Data Protection Impact Assessment (DPIA)
Flip cardA Data Protection Impact Assessment (DPIA) is a process designed to help organizations identify, assess, and mitigate data protection risks for projects or systems that involve the processing of personal data, especially where new technologies or large-scale processing is involved.
- Mandated by GDPR for high-risk processing activities.
- Proactive risk management tool.
- Focuses on risks to individuals' rights and freedoms.
Memory trick: DPIA: Protect people's data before you press play.
Privacy Impact Assessment (PIA)/Data Protection Impact Assessment (DPIA)
Flip cardA process designed to identify, assess, and mitigate privacy risks associated with new projects, systems, or technologies that involve the processing of personal data.
- Mandatory under regulations like GDPR for high-risk processing.
- Evaluates data types, processing methods, and potential impacts on individuals.
- Helps ensure 'privacy by design' and 'privacy by default'.
Memory trick: New data, new tech? A PIA/DPIA is the privacy check.
Broad Indemnification Clause
Flip cardA contractual provision in a CSA where the customer agrees to protect the CSP from all claims and liabilities arising from the customer's use of services, potentially even those caused by the CSP's own actions.
- Shifts significant financial and legal risk to the customer.
- Can make the customer liable for CSP's negligence or breaches.
- Requires careful negotiation to limit scope and include mutual indemnification.
Memory trick: Indemnify broadly, and you might pay for their folly.
Third-Party Audit Reports
Flip cardIndependent evaluations of a cloud service provider's security controls and processes against recognized standards, offering assurance to customers and auditors.
- Provide objective evidence of compliance.
- Examples include SOC 2 Type 2, ISO 27001.
- Crucial for regulatory compliance and due diligence.
Memory trick: To prove compliance, an independent report is the best defense.
Multi-Tenancy Privacy Risk
Flip cardMulti-tenancy in cloud computing, where multiple customers share the same underlying physical infrastructure, introduces privacy risks primarily related to the potential for data commingling, side-channel attacks, or unauthorized access if logical separation mechanisms fail or are compromised.
- Shared physical resources among multiple customers.
- Relies on strong logical isolation mechanisms.
- Primary risk: data leakage or unauthorized access between tenants.
Memory trick: Shared cloud means shared risks if separation fails.
Enterprise Risk Management (ERM)
Flip cardEnterprise Risk Management (ERM) is a comprehensive framework for identifying, assessing, and managing risks across an entire organization. It aims to provide a holistic view of risks, enabling better decision-making and resource allocation to achieve strategic objectives.
- Holistic view of all organizational risks.
- Integrates risk management across all departments/functions.
- Supports consistent decision-making and resource allocation.
Memory trick: ERM makes all risks speak the same language for resources.
NIST Risk Management Framework (RMF)
Flip cardA comprehensive, six-step process developed by NIST to manage security and privacy risks for information systems and organizations, applicable across diverse environments including hybrid and multi-cloud.
- Provides a structured approach to risk management.
- Applicable to federal agencies and widely adopted by private sector.
- Emphasizes continuous monitoring and risk posture awareness.
Memory trick: For holistic risk, NIST RMF is the best fit.
Business Associate Agreement (BAA)
Flip cardA legally required contract under HIPAA that defines the responsibilities of a 'business associate' (e.g., CSP) in protecting Protected Health Information (PHI) when performing services for a 'covered entity' (e.g., healthcare provider).
- Mandatory for HIPAA compliance.
- Outlines permitted uses and disclosures of PHI.
- Specifies security safeguards and breach notification procedures.
Memory trick: For PHI in the cloud, a BAA is the HIPAA crown.
Supply Chain Risk Management (SCRM)
Flip cardSupply Chain Risk Management (SCRM) is the systematic process of identifying, assessing, and mitigating risks associated with an organization's supply chain, particularly those involving third-party vendors and cloud service providers.
- Crucial for managing third-party dependencies.
- Starts with understanding the vendor landscape.
- Aims to protect data, systems, and operations from external threats.
Memory trick: Know your vendors before you trust their chains.
Jurisdictional Compliance
Flip cardAdhering to the specific data protection and privacy laws of multiple geographic regions where data is collected, processed, or stored.
- Laws vary significantly by country/region (e.g., GDPR, CCPA).
- Requires understanding data residency and processing locations.
- Often necessitates granular control strategies for data.
Memory trick: Different lands, different laws; classify and comply, not just encrypt and ignore.
Right to Audit Clause (CSA)
Flip cardA contractual provision in a Cloud Service Agreement that grants the customer the explicit right to conduct or commission independent security and compliance audits of the cloud service provider's environment.
- Crucial for customer oversight and due diligence.
- Ensures verification of CSP's security posture.
- Scope, frequency, and cost of audits are often negotiated.
Memory trick: To audit the cloud, the 'Right to Audit' must be loud.
Separation of Duties (SoD)
Flip cardA control principle that divides critical tasks or processes among multiple individuals or teams to prevent conflicts of interest, reduce the risk of fraud or error, and enhance accountability.
- Prevents a single point of failure or compromise.
- Ensures checks and balances in critical operations.
- Essential for strong governance and risk management.
Memory trick: For cloud governance, separate duties, or risks will rise.
Static Application Security Testing (SAST)
Flip cardSAST is a white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (build phase).
- Identifies vulnerabilities in custom code.
- Does not require a running application.
Memory trick: DevSecOps testing: SAST is 'Source Analysis', DAST is 'Dynamic Attack'.
Principle of Least Privilege (PoLP)
Flip cardA security principle requiring that a user or process be given only the minimum necessary authorization to perform its function.
- Reduces the attack surface.
- Limits the impact of a compromise.
- Applies to users, applications, and services.
Memory trick: Least Privilege: 'Just Enough, Not Too Much' access.
Secrets Management
Flip cardThe process and tools used to manage digital authentication credentials (secrets) such as API keys, passwords, and certificates, ensuring they are stored, accessed, and rotated securely.
- Centralized storage for sensitive credentials.
- Provides secure retrieval at runtime.
- Enables auditing and automated rotation.
Memory trick: API Keys need a 'Secret Vault' for safe keeping.
API Credential Management
Flip cardThe secure handling of API keys, tokens, and other credentials used to authenticate and authorize access to APIs, especially for automated processes.
- Adhere to least privilege.
- Use temporary credentials when possible.
- Avoid hardcoding credentials.
Memory trick: API Bots: 'Temporary Roles' for temporary tasks, never 'Root'.
Continuous Security in DevSecOps
Flip cardIntegrating security practices and automation throughout the entire software development and deployment pipeline to ensure continuous validation and feedback.
- Automates security checks.
- Provides rapid feedback.
- Shifts security left (earlier in SDLC).
Memory trick: DevSecOps: 'Always Scan, Always Comply' for continuous safety.
Microservices API Security
Flip cardSecuring communication and access between individual microservices, often relying on API-centric authentication and authorization mechanisms rather than just network controls.
- Requires granular access control.
- Often uses token-based authentication (e.g., JWT).
- IAM plays a central role in managing permissions.
Memory trick: Microservices need 'IAM to Talk', not just network walls.
Federated Identity
Flip cardA system that allows a user to authenticate with one identity provider and gain access to multiple independent systems or applications without needing to re-authenticate.
- Enables Single Sign-On (SSO).
- Relies on trusted identity providers.
- Improves user experience and reduces password management burden.
Memory trick: Federated Identity: 'One Key' to 'Many Doors'.
Secure File Uploads
Flip cardSecurity best practices for handling user-uploaded files to prevent malicious content from being stored, processed, or served to other users.
- Validate file type and content.
- Scan for malware.
- Store files outside the web root.
Memory trick: Uploaded Files: 'Scan and Sanitize' before they spread.
API Gateway Security
Flip cardAPI Gateways act as a single entry point for all API calls, enforcing security policies, managing traffic, and protecting backend services from various threats.
- Centralizes API security policies.
- Protects backend services from direct exposure.
- Enables fine-grained access control.
Memory trick: API Gateways are the 'Traffic Cops' for your microservices, directing and protecting.