Certified Cloud Security Professional (CCSP) flashcards
160 free flashcards. Tap a card to flip it.
Cross-Site Request Forgery (CSRF)
Flip cardAn attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
- Exploits trust in a user's browser.
- Targets state-changing requests.
- Mitigated by anti-CSRF tokens.
Memory trick: CSRF: 'Don't Get Phished', use a 'Token Shield'.
Threat Modeling
Flip cardA structured process for identifying potential threats, vulnerabilities, and countermeasures at the design stage of software development.
- Proactive security activity.
- Focuses on identifying design flaws.
- Helps prioritize security efforts.
Memory trick: Design Phase: 'Draw the Threats' before you build.
PCI DSS Requirement 6.5
Flip cardA PCI DSS requirement mandating that applications be developed securely by addressing common coding vulnerabilities and preventing common attack methods.
- Focuses on application-layer security.
- Requires secure coding practices and vulnerability remediation.
- Often aligns with OWASP Top 10.
Memory trick: PCI 6.5: 'Secure Code' is the 'Golden Rule' for apps.
SOC 2 Type II
Flip cardAn auditing report that assesses a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy over a period of time.
- Provides assurance to user entities on the effectiveness of controls.
- Covers the Trust Services Criteria, including physical and environmental security.
- Widely used by cloud providers to demonstrate security posture.
Memory trick: SOC 2 is the 'Stamp of Approval' for data center 'Security' and 'Trust'.
API Gateway
Flip cardAn API Gateway acts as a single entry point for all API calls, handling routing, composition, and security concerns such as authentication, authorization, rate limiting, and caching.
- Centralizes API security policies.
- Protects backend services.
- Provides traffic management and monitoring.
Memory trick: API Gateway is the main GATeway for all API calls.
Serverless Computing (FaaS) for IR
Flip cardLeveraging Function as a Service (FaaS) platforms in the cloud to execute incident response tasks, offering automatic scaling, pay-per-execution, and reduced operational overhead.
- Ideal for bursty, event-driven workloads (e.g., log processing, alert enrichment).
- Automatically scales up and down based on demand.
- Reduces infrastructure management overhead.
Memory trick: Serverless is like a 'fire and forget' missile for scaling.
Function as a Service (FaaS) for IR
Flip cardLeveraging serverless functions to automate specific, event-driven incident response tasks in the cloud.
- Event-driven execution.
- No server management.
- Scales automatically, cost-effective for episodic tasks.
Memory trick: Functions are the F-astest for 'F'ire-fighting tasks.
Volatile Data Collection
Flip cardThe process of collecting data from a running system that will be lost once the system is powered off or restarted, such as RAM contents, CPU registers, and network session information.
- Must be collected first in a forensic investigation (order of volatility).
- Provides insights into active processes, malware, and user sessions.
- Requires specialized tools and techniques for live system acquisition.
Memory trick: Volatile data is like 'Smoke' from the fire; you catch it before it 'Disappears'.
Cloud Forensics - Evidence Preservation
Flip cardThe process of securing and maintaining the integrity of digital evidence from cloud environments to ensure its admissibility in legal or disciplinary proceedings.
- Crucial for maintaining chain of custody.
- Often involves creating immutable copies (snapshots/images) of disks.
- Avoids altering the original compromised system.
Memory trick: Evidence is like a delicate flower; preserve it carefully.
Serverless Security Monitoring
Flip cardFocuses on leveraging cloud provider-native logging, metrics, and API integrations due to the ephemeral and managed nature of serverless functions.
- Traditional agents are impractical.
- Relies heavily on cloud provider logs and metrics.
- Integrates with SIEM/observability platforms.
Memory trick: Look to the cloud's own logs for serverless secrets.
Cloud SIEM Data Ingestion & Parsing
Flip cardThe ability of a cloud-native Security Information and Event Management (SIEM) system to collect, process, and structure security event data from a wide variety of cloud services and on-premises sources.
- Crucial first step for any SIEM functionality.
- Handles different log formats and APIs.
- Enables subsequent normalization and correlation.
Memory trick: SIEM first needs to 'eat' all the data to make sense of it.
Shift Left Security
Flip cardThe practice of integrating security activities and considerations early in the software development lifecycle (SDLC), ideally starting in the design and planning phases.
- Reduces cost of fixing vulnerabilities.
- Builds security in, rather than bolting it on.
- Emphasizes proactive security measures.
Memory trick: Shift Left means secure from the start, not just the end.
Data Localization
Flip cardThe requirement for data to be stored and processed within the geographical boundaries of a specific country or region.
- Driven by data residency and privacy regulations (e.g., GDPR, CCPA).
- Impacts cloud architecture design, especially for multi-national deployments.
- Requires careful planning for data storage, processing, and transfer across borders.
Memory trick: SIEM's 'Location, Location, Location' for data is key for compliance.
Continuous Data Replication (CDR)
Flip cardA disaster recovery strategy that continuously copies data changes from a primary location to a secondary location, ensuring that the secondary site is always nearly identical to the primary, resulting in very low RPO.
- Achieves very low RPO (seconds to minutes).
- Can be synchronous or asynchronous.
- Often paired with active-passive or active-active DR strategies.
Memory trick: Continuous replication is like having a twin, always up-to-date.
Cloud Security Configuration Management
Flip cardThe process of defining, implementing, and continuously monitoring security configurations for cloud resources to ensure compliance with policies and standards.
- Automates the enforcement of security baselines.
- Detects and remediates configuration drifts.
- Crucial for maintaining a consistent security posture and compliance.
Memory trick: Configuration Management is the 'Blueprint Inspector' for cloud settings.
Distributed Tracing with SIEM Integration
Flip cardDistributed tracing tracks requests across multiple services in a distributed system, and integrating this data into a SIEM enables centralized security analysis and incident detection.
- Provides end-to-end visibility of request flows.
- Crucial for debugging and securing microservices.
- SIEM integration correlates security events for incident response.
Memory trick: Tracing services, SIEM secures everything.
Service Mesh with mTLS
Flip cardA dedicated infrastructure layer for handling service-to-service communication, where Mutual TLS (mTLS) is automatically provisioned and enforced by sidecar proxies for mutual authentication and encryption between microservices.
- Automates mTLS for inter-service communication.
- Offloads security concerns from application developers.
- Provides granular traffic management and observability.
Memory trick: Think of a tiny security guard (proxy) for every microservice, checking IDs and encrypting whispers.
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable duration of time that a system, application, or service can be unavailable after an incident.
- Expressed in time (e.g., hours, days).
- Dictates how quickly systems must be restored.
- A critical metric for business continuity planning.
Memory trick: RTO is about 'Time to Operate' again.
Principle of Least Privilege (PoLP) for Serverless
Flip cardApplying PoLP in serverless architectures means granting each function only the specific, minimal permissions required to perform its intended task, typically via IAM roles.
- Reduces the attack surface.
- Limits the impact of a compromised function.
- Requires granular access control definitions.
Memory trick: Least Privilege = Least Power.
Log Normalization
Flip cardThe process of converting disparate log formats from various sources into a common, structured format for easier analysis and correlation.
- Essential for SIEM effectiveness.
- Involves parsing and mapping fields.
- Enables consistent querying and reporting.
Memory trick: Normalize the noise so your SIEM can make sense of it.
Secrets Management for External APIs
Flip cardUsing a dedicated secrets management service to securely store, retrieve, and manage credentials (e.g., API keys, tokens) required for an application to interact with external, third-party APIs.
- Centralizes diverse credential types.
- Enhances security by separating credentials from code.
- Supports automated rotation and auditing.
Memory trick: Secrets Manager safeguards all API secrets.
User and Entity Behavior Analytics (UEBA)
Flip cardA security solution that uses machine learning and analytics to detect anomalous behavior by users and entities (e.g., applications, hosts) within an organization's cloud environment.
- Focuses on identifying insider threats and targeted attacks.
- Establishes a baseline of normal behavior.
- Alerts on deviations from baselines.
Memory trick: UEBA watches users like a hawk watches its prey.
Secrets Management Service
Flip cardA cloud service designed to securely store, manage, and retrieve sensitive application credentials and configuration data (secrets), often including automatic rotation.
- Centralized storage for secrets.
- Integrates with IAM for access control.
- Supports automatic key/secret rotation.
Memory trick: Secrets Manager keeps app secrets safe and sound.
Service Mesh with Mutual TLS (mTLS)
Flip cardA service mesh provides network-based communication control, and mTLS within it establishes mutual authentication and encryption between services using certificates.
- Automates service identity and certificate management.
- Encrypts all inter-service communication.
- Enforces policies at the network layer.
Memory trick: Mesh with mTLS makes microservices mutually trusted and secure.
Runtime Application Self-Protection (RASP)
Flip cardA security technology that integrates into an application's runtime environment, continuously monitoring its execution and detecting/blocking attacks in real-time from within the application itself.
- Provides immediate, in-application protection.
- Effective against zero-day attacks and sophisticated threats.
- Low false-positive rates due to deep context of application logic.
Memory trick: RASP is like a bodyguard *inside* the application, always watching.
Cloud Key Management Service (KMS)
Flip cardA cloud-native service that helps you create and control the encryption keys used to protect your data.
- Manages the lifecycle of cryptographic keys.
- Integrates with hardware security modules (HSMs) for strong key protection.
- Supports various encryption scenarios, including data at rest and in transit.
Memory trick: KMS holds the 'Keys' to your cloud kingdom's data.
Cloud Account/Subscription Isolation
Flip cardA multi-tenancy isolation strategy where different applications or environments are deployed into entirely separate cloud accounts or subscriptions, providing the highest level of administrative and security boundary isolation.
- Strongest form of isolation.
- Separate IAM, networking, billing boundaries.
- Protects against cross-account compromise.
Memory trick: Each application gets its own castle, with its own drawbridge and guards, not just a room in a shared palace.
Incident Response - Containment
Flip cardThe phase of incident response focused on limiting the scope and impact of an incident, preventing further damage.
- Aims to stop the attack and isolate affected systems.
- Often involves immediate technical actions like blocking traffic or isolating networks.
- Must be executed quickly to minimize business disruption.
Memory trick: When the 'Flood' hits, build the 'Dam' first!
Cloud SIEM
Flip cardA Security Information and Event Management (SIEM) system adapted for cloud environments, collecting and analyzing security logs and events from various cloud services and infrastructure.
- Centralizes security data from diverse cloud sources.
- Enables real-time threat detection and incident response.
- Supports compliance reporting and forensic analysis.
Memory trick: SIEM's the 'Eye' in the cloud, seeing all logs, connecting all dots.
Server-Side Encryption with Customer-Managed Keys (SSE-KMS)
Flip cardA method where data is encrypted by the cloud provider's service, but the encryption keys are generated and managed by the customer using a dedicated Key Management Service.
- Keys are separate from data.
- Customer retains control over key lifecycle.
- KMS provides auditing and access control for keys.
Memory trick: KMS gives customers total Key Management for Secure data.
Compliance Audit
Flip cardAn independent review to determine whether an organization's operations, processes, and controls adhere to specific regulatory requirements, industry standards, or internal policies.
- Verifies adherence to laws (e.g., HIPAA), regulations (e.g., GDPR), and standards (e.g., PCI DSS).
- Often conducted by third-party auditors.
- Provides assurance to customers and stakeholders.
Memory trick: Compliance audits check boxes, like a checklist.
Cloud Activity Logging
Flip cardCloud services that record API calls and management events for cloud resources, providing an audit trail of actions taken within the cloud environment.
- Captures 'who, what, when, where' for cloud resource operations.
- Logs are typically immutable to ensure integrity for forensic purposes.
- Essential for security auditing, compliance, and incident response.
Memory trick: Cloud 'Trail' leaves breadcrumbs for the forensic 'Detective'.
Identity Federation
Flip cardA system that allows users to authenticate once with a trusted identity provider (IdP) and then gain access to multiple service providers (SPs) without re-authenticating. It establishes a trust relationship between domains.
- Single Sign-On (SSO) capability.
- Reduces credential sprawl and management overhead.
- Commonly uses protocols like SAML, OpenID Connect.
Memory trick: Let your home ID card open cloud doors, no need for a new cloud passport.
Secure File Uploads (Server-Side Processing)
Flip cardImplementing robust server-side processing for uploaded files, including validation of type, size, and content, malware scanning, and sanitization (e.g., metadata stripping).
- Client-side checks are insufficient.
- Prevents malware injection and privacy leaks.
- Crucial for data integrity and security.
Memory trick: Server-side checks clean files, keeping everything safe.
Multi-Tenant Data Isolation (Logical)
Flip cardEnsuring that each tenant's data in a multi-tenant application is logically separated and inaccessible to other tenants, typically achieved through database schema design or application-level controls.
- Crucial for data confidentiality and integrity.
- Prevents cross-tenant data leakage.
- Requires careful design at the data layer.
Memory trick: Schemas keep tenants' data isolated and secure.
Software Composition Analysis (SCA)
Flip cardSCA is an automated process that identifies and inventories open-source and third-party components in a codebase and checks for known vulnerabilities in those components.
- Focuses on dependencies, not custom code.
- Integrated into CI/CD pipelines.
- Helps manage supply chain security risks.
Memory trick: SCA checks software components for problems.
Incident Response - Eradication
Flip cardThe phase of incident response focused on eliminating the root cause of the incident and removing all malicious components from the affected systems.
- Occurs after containment and analysis.
- Aims to prevent recurrence.
- Precedes the recovery phase.
Memory trick: I C E R R L: I See Every Root Removed, Later.
Mobile App Attestation / Client-Side Certificate Pinning
Flip cardTechniques used to verify that API requests originate from a legitimate, untampered version of a mobile application, preventing impersonation by malicious clients.
- Verifies app integrity and authenticity.
- Protects against API abuse from fake clients.
- Hardens client-side security.
Memory trick: Attestation confirms the App is real.
Client-Side Encryption (CSE)
Flip cardEncryption performed by the client application before data is sent to the cloud, ensuring the cloud provider never sees unencrypted data or encryption keys. The client maintains full control over the keys.
- Data encrypted before leaving client environment.
- Client holds and manages the encryption keys.
- Cloud provider stores encrypted data only.
Memory trick: To truly own your cloud data lock, keep the key in your hand, not in the cloud's.
Database Transaction Logs
Flip cardRecords of all changes and operations performed on a database, including data modifications, queries, user sessions, and timestamps, used for auditing, recovery, and forensic analysis.
- Essential for understanding 'what data' was accessed and 'by whom'.
- Provides granular detail on database activity.
- Crucial for data breach impact assessment.
Memory trick: Database logs tell the story of every data touch.