Free knowledge base

Certified Cloud Security Professional (CCSP) — key terms, tricks & tips

Everything from the course in one searchable place: 293 entries. Use it to review before a practice test or look up a word you forgot.

293 results

Key term

CCSP

Certified Cloud Security Professional, an advanced cloud security certification.

Getting Started: CCSP Exam Essentials

Key term

(ISC)²

International Information System Security Certification Consortium, provider of CCSP.

Getting Started: CCSP Exam Essentials

Key term

CBK

Common Body of Knowledge, the comprehensive outline of exam topics.

Getting Started: CCSP Exam Essentials

Key term

Domain

A major topic area within the CCSP CBK, e.g., Cloud Data Security.

Getting Started: CCSP Exam Essentials

Key term

CPE

Continuing Professional Education, credits required to maintain certification.

Getting Started: CCSP Exam Essentials

Key term

AMF

Annual Maintenance Fee, required yearly to keep certification active.

Getting Started: CCSP Exam Essentials

Key term

Shared Responsibility Model

Defines security duties between cloud provider and customer.

Getting Started: CCSP Exam Essentials

Memory trick

Understanding the CCSP Certification and Exam

To remember the six CCSP domains, think: 'CADS OIL' — Concepts, Architecture, Data, Security Operations, Infrastructure, Legal.

Getting Started: CCSP Exam Essentials

Exam tip

Understanding the CCSP Certification and Exam

The exam will test your understanding of the *purpose* of each CCSP domain, not just memorizing their names. Look for questions asking about the *application* of knowledge from specific domains.

Getting Started: CCSP Exam Essentials

Common mistake

Understanding the CCSP Certification and Exam

Underestimating the experience requirements; ensure your work history aligns with the stated criteria.

Getting Started: CCSP Exam Essentials

Common mistake

Understanding the CCSP Certification and Exam

Focusing solely on technical details and neglecting governance, risk, and compliance aspects.

Getting Started: CCSP Exam Essentials

Common mistake

Understanding the CCSP Certification and Exam

Not understanding the shared responsibility model, which is fundamental to all cloud security discussions.

Getting Started: CCSP Exam Essentials

Key term

Active Learning

Engaging with material through notes, practice, and discussion.

Getting Started: CCSP Exam Essentials

Key term

Exam Blueprint

Official document outlining exam domains, topics, and weighting.

Getting Started: CCSP Exam Essentials

Key term

Knowledge Gap

An area where understanding or information is lacking.

Getting Started: CCSP Exam Essentials

Key term

Time Allocation

Distributing study hours across different exam domains.

Getting Started: CCSP Exam Essentials

Key term

Pretest Items

Unscored questions on the exam used for future exam development.

Getting Started: CCSP Exam Essentials

Key term

Domain Weighting

The percentage of exam questions from a specific CCSP domain.

Getting Started: CCSP Exam Essentials

Memory trick

CCSP Exam Strategies and Study Plan Development

To remember the study cycle: Assess, Set, Create, Act, Review, Practice (ASCRAP).

Getting Started: CCSP Exam Essentials

Exam tip

CCSP Exam Strategies and Study Plan Development

The CCSP exam tests your ability to apply cloud security concepts, not just memorize definitions. Look for scenario-based questions and choose the 'best' answer among plausible options, often involving risk management or compliance implications.

Getting Started: CCSP Exam Essentials

Common mistake

CCSP Exam Strategies and Study Plan Development

Underestimating the time required for comprehensive study across all six domains.

Getting Started: CCSP Exam Essentials

Common mistake

CCSP Exam Strategies and Study Plan Development

Solely relying on passive study methods like reading without active engagement or practice.

Getting Started: CCSP Exam Essentials

Common mistake

CCSP Exam Strategies and Study Plan Development

Ignoring the official exam blueprint, leading to disproportionate study effort on less weighted domains.

Getting Started: CCSP Exam Essentials

Key term

IaaS

Infrastructure as a Service; virtualized computing resources over the internet.

Cloud Fundamentals and Secure Design

Key term

PaaS

Platform as a Service; platform for developing, running, and managing applications.

Cloud Fundamentals and Secure Design

Key term

SaaS

Software as a Service; applications delivered over the internet.

Cloud Fundamentals and Secure Design

Key term

NIST SP 800-145

Definitive standard for cloud computing definition and characteristics.

Cloud Fundamentals and Secure Design

Key term

Rapid Elasticity

Cloud resources scale quickly up or down based on demand.

Cloud Fundamentals and Secure Design

Key term

Measured Service

Resource usage is monitored and reported for billing and optimization.

Cloud Fundamentals and Secure Design

Key term

Hybrid Cloud

Combines two or more distinct cloud infrastructures.

Cloud Fundamentals and Secure Design

Key term

Cloud Broker

Manages cloud service use, performance, and delivery.

Cloud Fundamentals and Secure Design

Memory trick

Cloud Computing Concepts & Reference Architecture

For NIST characteristics, remember 'O-B-R-R-M': On-demand, Broad access, Resource pooling, Rapid elasticity, Measured service. It's like ordering a pizza: On-demand, delivered Broadly, from a shared Resource pool, Rapidly, and you're Measured for what you eat!

Cloud Fundamentals and Secure Design

Exam tip

Cloud Computing Concepts & Reference Architecture

Memorize the five NIST essential characteristics of cloud computing and be able to distinguish them from cloud service or deployment models. The exam frequently tests your understanding of these core definitions.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Concepts & Reference Architecture

Confusing the NIST essential characteristics with service models (IaaS, PaaS, SaaS) or deployment models (public, private).

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Concepts & Reference Architecture

Incorrectly assigning responsibility in the shared responsibility model for different service models (e.g., thinking the provider manages OS in IaaS).

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Concepts & Reference Architecture

Not understanding the role of a Cloud Broker versus a Cloud Provider in the CSA Reference Architecture.

Cloud Fundamentals and Secure Design

Key term

Security by Design

Integrating security considerations from the initial design phase.

Cloud Fundamentals and Secure Design

Key term

Defense in Depth

Layering multiple security controls to protect assets.

Cloud Fundamentals and Secure Design

Key term

Least Privilege

Granting minimum necessary permissions to users or systems.

Cloud Fundamentals and Secure Design

Key term

Confidentiality

Protecting information from unauthorized disclosure.

Cloud Fundamentals and Secure Design

Key term

Integrity

Ensuring information is accurate and unaltered.

Cloud Fundamentals and Secure Design

Key term

Availability

Ensuring systems and data are accessible when needed.

Cloud Fundamentals and Secure Design

Memory trick

Cloud Security Concepts & Design Principles

CIA Triad: Confidentiality, Integrity, Availability. Remember 'C-I-A' as your 'Cloud Information Assurance' foundation!

Cloud Fundamentals and Secure Design

Exam tip

Cloud Security Concepts & Design Principles

The CCSP exam frequently tests the nuances of the shared responsibility model across different service models (IaaS, PaaS, SaaS). Memorize who is responsible for what in each model, especially for network controls, operating system patching, and data encryption.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Concepts & Design Principles

Assuming the cloud provider is solely responsible for all security aspects of your cloud deployment.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Concepts & Design Principles

Failing to implement security controls for resources that fall under the customer's responsibility.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Concepts & Design Principles

Not applying the principle of least privilege, leading to overly permissive access rights.

Cloud Fundamentals and Secure Design

Key term

Multi-tenancy

Multiple customers sharing the same underlying infrastructure.

Cloud Fundamentals and Secure Design

Key term

Data Residency

Geographical location where data is physically stored.

Cloud Fundamentals and Secure Design

Key term

Cloud Sprawl

Uncontrolled proliferation of cloud resources and accounts.

Cloud Fundamentals and Secure Design

Key term

Vendor Lock-in

Dependence on a single cloud provider, hindering migration.

Cloud Fundamentals and Secure Design

Key term

IAM

Identity and Access Management; controls who can do what.

Cloud Fundamentals and Secure Design

Key term

Data Leakage

Unintended exposure of sensitive information.

Cloud Fundamentals and Secure Design

Memory trick

Cloud Computing Security Challenges

SHARED: S-Security OF the cloud, H-Host OS, A-Applications, R-Responsibility IN the cloud, E-Encryption, D-Data.

Cloud Fundamentals and Secure Design

Exam tip

Cloud Computing Security Challenges

Memorize the core tenets of the Shared Responsibility Model for IaaS, PaaS, and SaaS. The exam often tests your ability to identify who is responsible for specific security controls under each service model.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Security Challenges

Assuming the cloud provider is responsible for all security aspects, especially data security.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Security Challenges

Not implementing strong Identity and Access Management (IAM) controls, leading to over-privileged accounts.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Computing Security Challenges

Ignoring data residency and compliance requirements when selecting cloud regions.

Cloud Fundamentals and Secure Design

Key term

Multi-Factor Authentication (MFA)

Requires two or more verification factors for access.

Cloud Fundamentals and Secure Design

Key term

Data Loss Prevention (DLP)

Tools and processes to prevent sensitive data exfiltration.

Cloud Fundamentals and Secure Design

Key term

Cloud Security Posture Management (CSPM)

Tools to identify and remediate cloud configuration risks.

Cloud Fundamentals and Secure Design

Key term

Web Application Firewall (WAF)

Protects web applications from common attacks.

Cloud Fundamentals and Secure Design

Key term

Encryption at Rest

Securing data stored in storage systems.

Cloud Fundamentals and Secure Design

Key term

Encryption in Transit

Securing data moving across networks.

Cloud Fundamentals and Secure Design

Memory trick

Cloud Security Best Practices

S.P.I.C.E. for Cloud Security: Shared Responsibility, Protection of Data, Identity Management, Continuous Monitoring, Education.

Cloud Fundamentals and Secure Design

Exam tip

Cloud Security Best Practices

The exam frequently tests the nuances of the Shared Responsibility Model across IaaS, PaaS, and SaaS. Memorize which party is responsible for what in each service model; pay special attention to where responsibilities shift, such as OS patching in PaaS.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Best Practices

Assuming the cloud provider handles all security, especially for data and applications.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Best Practices

Neglecting to implement MFA for all privileged accounts.

Cloud Fundamentals and Secure Design

Common mistake

Cloud Security Best Practices

Failing to regularly review and update IAM policies, leading to 'permission creep'.

Cloud Fundamentals and Secure Design

Key term

Object Storage

Scalable storage for unstructured data, accessed via APIs.

Securing Data in the Cloud

Key term

Block Storage

Raw storage attached to VMs, ideal for databases.

Securing Data in the Cloud

Key term

File Storage

Shared file system access (NFS/SMB) for applications.

Securing Data in the Cloud

Key term

Tokenization

Replaces sensitive data with non-sensitive tokens.

Securing Data in the Cloud

Key term

Data Masking

Creates realistic but fake data for non-production use.

Securing Data in the Cloud

Key term

Homomorphic Encryption

Computes on encrypted data without decryption.

Securing Data in the Cloud

Key term

Data Sanitization

Irreversibly removes data from storage media.

Securing Data in the Cloud

Memory trick

Cloud Data Storage & Data Security Technologies

O-B-F: Objects for Big files, Blocks for Databases, Files for Shares. Remember the order for common use cases!

Securing Data in the Cloud

Exam tip

Cloud Data Storage & Data Security Technologies

The exam frequently asks about the appropriate cloud storage type for a given scenario (e.g., 'Which storage type is best for backups?' or 'Which is best for a database?'). Memorize the characteristics and primary use cases for object, block, and file storage. Also, understand the security implications of each.

Securing Data in the Cloud

Common mistake

Cloud Data Storage & Data Security Technologies

Confusing object storage with file storage: Object storage is API-driven and flat, while file storage is hierarchical with shared access.

Securing Data in the Cloud

Common mistake

Cloud Data Storage & Data Security Technologies

Neglecting access controls for object storage: Public S3 buckets are a common misconfiguration leading to data breaches.

Securing Data in the Cloud

Common mistake

Cloud Data Storage & Data Security Technologies

Assuming cloud provider handles all data security: Remember the shared responsibility model; customer is always responsible for data itself.

Securing Data in the Cloud

Key term

Data Discovery

Process of locating sensitive data across cloud environments.

Securing Data in the Cloud

Key term

Data Classification

Categorizing data based on sensitivity and regulatory requirements.

Securing Data in the Cloud

Key term

IRM

Information Rights Management; persistent data protection with embedded policies.

Securing Data in the Cloud

Key term

DRM

Digital Rights Management; often used for media, similar to IRM for enterprise data.

Securing Data in the Cloud

Key term

Persistent Protection

Data protection that stays with the data, regardless of location.

Securing Data in the Cloud

Key term

Shadow IT

IT systems/solutions used without explicit organizational approval.

Securing Data in the Cloud

Key term

Granular Control

Fine-grained management over data access and usage permissions.

Securing Data in the Cloud

Key term

PII

Personally Identifiable Information; data that can identify an individual.

Securing Data in the Cloud

Memory trick

Data Discovery, Classification & Rights Management

Discover, Classify, Apply Rights (D.C.A.R.) – The car drives your data security home!

Securing Data in the Cloud

Exam tip

Data Discovery, Classification & Rights Management

The exam often tests the difference between data at rest, in transit, and in use, and how IRM specifically protects data 'in use' or after it leaves an authorized perimeter. Be prepared to identify scenarios where IRM is the most appropriate control.

Securing Data in the Cloud

Common mistake

Data Discovery, Classification & Rights Management

Failing to continuously discover data, leading to unknown sensitive data stores.

Securing Data in the Cloud

Common mistake

Data Discovery, Classification & Rights Management

Implementing data classification without corresponding enforcement mechanisms like IRM.

Securing Data in the Cloud

Common mistake

Data Discovery, Classification & Rights Management

Confusing traditional access control lists (ACLs) with the persistent protection offered by IRM/DRM.

Securing Data in the Cloud

Key term

Data in Use

Data being processed by applications or users (e.g., RAM).

Securing Data in the Cloud

Key term

Data in Motion

Data being transmitted across networks (e.g., email, file transfers).

Securing Data in the Cloud

Key term

Data at Rest

Data stored on physical or logical media (e.g., databases, files).

Securing Data in the Cloud

Key term

Cloud Access Security Broker (CASB)

Security policy enforcement point between cloud users and cloud services.

Securing Data in the Cloud

Key term

Data Retention Policy

Rules defining how long data must be kept and how to dispose of it.

Securing Data in the Cloud

Key term

Data Archiving

Moving inactive data to long-term, cost-effective storage for compliance/history.

Securing Data in the Cloud

Key term

Legal Hold

A process to preserve all forms of relevant information when litigation is pending.

Securing Data in the Cloud

Memory trick

Data Loss Prevention, Retention & Archiving

To remember DLP's coverage: 'DLP is DIM' - Data In use, Data In Motion, Data at Rest.

Securing Data in the Cloud

Exam tip

Data Loss Prevention, Retention & Archiving

The exam frequently tests the distinction between backup and archiving. Remember: backup is for disaster recovery (operational continuity), archiving is for long-term retention and compliance (historical record). Also, be ready to identify where DLP is applied (in use, in motion, at rest) and the role of CASBs.

Securing Data in the Cloud

Common mistake

Data Loss Prevention, Retention & Archiving

Confusing data backup with data archiving; they have different purposes and access patterns.

Securing Data in the Cloud

Common mistake

Data Loss Prevention, Retention & Archiving

Implementing DLP without proper data classification, leading to false positives or missed sensitive data.

Securing Data in the Cloud

Common mistake

Data Loss Prevention, Retention & Archiving

Failing to align cloud retention policies with legal and regulatory requirements, resulting in non-compliance.

Securing Data in the Cloud

Key term

Cryptography

Science of securing data and communication.

Securing Data in the Cloud

Key term

Symmetric Encryption

Uses a single, shared key for encryption/decryption.

Securing Data in the Cloud

Key term

Asymmetric Encryption

Uses public/private key pair for encryption/decryption.

Securing Data in the Cloud

Key term

Hashing

One-way function for data integrity verification.

Securing Data in the Cloud

Key term

Digital Signature

Ensures authenticity, integrity, and non-repudiation.

Securing Data in the Cloud

Key term

Key Management Service (KMS)

Cloud service for managing cryptographic keys.

Securing Data in the Cloud

Key term

Hardware Security Module (HSM)

Secure physical/virtual device for key operations.

Securing Data in the Cloud

Key term

Key Rotation

Periodically replacing cryptographic keys.

Securing Data in the Cloud

Memory trick

Cryptographic Solutions & Key Management

KMS: 'Keep My Secrets' - Cloud Key Management Service helps you keep your encryption keys safe and sound!

Securing Data in the Cloud

Exam tip

Cryptographic Solutions & Key Management

For the CCSP exam, focus on the differences between symmetric and asymmetric encryption (speed, key distribution), the purposes of hashing (integrity) and digital signatures (authenticity, integrity, non-repudiation), and the key management lifecycle steps. Understand the role of KMS and HSMs offered by cloud providers.

Securing Data in the Cloud

Common mistake

Cryptographic Solutions & Key Management

Confusing symmetric and asymmetric encryption use cases; remember symmetric for bulk, asymmetric for key exchange/signatures.

Securing Data in the Cloud

Common mistake

Cryptographic Solutions & Key Management

Neglecting key management best practices, leading to compromised keys or data.

Securing Data in the Cloud

Common mistake

Cryptographic Solutions & Key Management

Assuming all cloud data is automatically encrypted by default without explicit configuration.

Securing Data in the Cloud

Key term

Virtual Private Cloud (VPC)

Logically isolated network within a public cloud provider's infrastructure.

Cloud Platform and Infrastructure Security

Key term

Software-Defined Networking (SDN)

Network management through software control, abstracting hardware.

Cloud Platform and Infrastructure Security

Key term

Network Access Control List (NACL)

Stateless firewall at the subnet level, controlling inbound/outbound traffic.

Cloud Platform and Infrastructure Security

Key term

Security Group

Stateful firewall at the instance level, controlling traffic to/from virtual machines.

Cloud Platform and Infrastructure Security

Key term

Micro-segmentation

Applying granular security policies to individual workloads or applications.

Cloud Platform and Infrastructure Security

Key term

Zero Trust

Security model that assumes no implicit trust, verifying all access requests.

Cloud Platform and Infrastructure Security

Memory trick

Cloud Infrastructure Components & Network Security

NACLs are 'No Acknowledgment, Control List' – they don't remember past connections. Security Groups are 'Smart Guardians' – they remember and allow return traffic.

Cloud Platform and Infrastructure Security

Exam tip

Cloud Infrastructure Components & Network Security

Memorize the distinction between stateless (NACLs) and stateful (Security Groups) firewalls. NACLs process rules in order and apply to all instances in a subnet, while Security Groups evaluate all rules and apply to specific instances.

Cloud Platform and Infrastructure Security

Common mistake

Cloud Infrastructure Components & Network Security

Over-privileging Security Groups or NACLs, allowing 'any-any' traffic.

Cloud Platform and Infrastructure Security

Common mistake

Cloud Infrastructure Components & Network Security

Failing to segment networks, putting all resources in a single flat network.

Cloud Platform and Infrastructure Security

Common mistake

Cloud Infrastructure Components & Network Security

Confusing the shared responsibility model, assuming the cloud provider secures everything.

Cloud Platform and Infrastructure Security

Common mistake

Cloud Infrastructure Components & Network Security

Not logging network flow data for security analysis and incident response.

Cloud Platform and Infrastructure Security

Key term

Hypervisor

Software that creates and runs virtual machines (VMs).

Cloud Platform and Infrastructure Security

Key term

VM Escape

An attack allowing a VM to break out of its isolation to access the hypervisor or other VMs.

Cloud Platform and Infrastructure Security

Key term

Type 1 Hypervisor

Runs directly on physical hardware; bare-metal hypervisor.

Cloud Platform and Infrastructure Security

Key term

Type 2 Hypervisor

Runs on top of a host operating system; hosted hypervisor.

Cloud Platform and Infrastructure Security

Memory trick

Compute, Storage & Virtualization Security

C-S-V: 'Compute, Store, Virtualize' – Remember these three core areas are fundamental to cloud security, like the CSV file format is fundamental to data.

Cloud Platform and Infrastructure Security

Exam tip

Compute, Storage & Virtualization Security

Memorize the core responsibilities under the Shared Responsibility Model for IaaS, PaaS, and SaaS, especially how compute and storage security duties shift. Keywords: 'customer responsibility', 'provider responsibility', 'guest OS', 'hypervisor'.

Cloud Platform and Infrastructure Security

Common mistake

Compute, Storage & Virtualization Security

Assuming the cloud provider handles all security, especially for guest operating systems and application code.

Cloud Platform and Infrastructure Security

Common mistake

Compute, Storage & Virtualization Security

Not properly configuring access control for storage buckets, leading to public exposure of sensitive data.

Cloud Platform and Infrastructure Security

Common mistake

Compute, Storage & Virtualization Security

Neglecting to patch virtual machines regularly, leaving them vulnerable to known exploits.

Cloud Platform and Infrastructure Security

Key term

Container

Isolated, portable software package with app and dependencies.

Cloud Platform and Infrastructure Security

Key term

Serverless Computing

Cloud execution model where provider manages infrastructure.

Cloud Platform and Infrastructure Security

Key term

Container Image

Read-only template for creating containers.

Cloud Platform and Infrastructure Security

Key term

Container Registry

Repository for storing and distributing container images.

Cloud Platform and Infrastructure Security

Key term

Management Plane

Interface for controlling cloud resources via APIs/consoles.

Cloud Platform and Infrastructure Security

Key term

FaaS

Functions-as-a-Service, a serverless computing category.

Cloud Platform and Infrastructure Security

Key term

Runtime Security

Protecting applications during their execution.

Cloud Platform and Infrastructure Security

Memory trick

Container, Serverless & Management Plane Security

To secure your CLOUD: Containers (secure images), Least Privilege (IAM), Orchestration (Kubernetes security), Users (MFA), Data (encryption).

Cloud Platform and Infrastructure Security

Exam tip

Container, Serverless & Management Plane Security

The exam often tests the shared responsibility model for serverless and containers. Remember that while the cloud provider secures the underlying infrastructure, the customer is always responsible for their code, configurations, and data within these environments.

Cloud Platform and Infrastructure Security

Common mistake

Container, Serverless & Management Plane Security

Assuming containers are inherently secure due to isolation.

Cloud Platform and Infrastructure Security

Common mistake

Container, Serverless & Management Plane Security

Neglecting to scan container images for vulnerabilities before deployment.

Cloud Platform and Infrastructure Security

Common mistake

Container, Serverless & Management Plane Security

Granting overly broad permissions to serverless functions or management plane users.

Cloud Platform and Infrastructure Security

Key term

RTO (Recovery Time Objective)

Maximum acceptable downtime after a disruptive event.

Cloud Platform and Infrastructure Security

Key term

RPO (Recovery Point Objective)

Maximum acceptable data loss after a disruptive event.

Cloud Platform and Infrastructure Security

Key term

Pilot Light

BCDR strategy with minimal core services running in standby region.

Cloud Platform and Infrastructure Security

Key term

Warm Standby

BCDR strategy with scaled-down but running services in standby region.

Cloud Platform and Infrastructure Security

Key term

Hot Standby

BCDR strategy with fully operational, synchronized services in standby region.

Cloud Platform and Infrastructure Security

Key term

CSPM (Cloud Security Posture Management)

Tools for continuous monitoring of cloud configurations for risks.

Cloud Platform and Infrastructure Security

Key term

Business Impact Analysis (BIA)

Process to identify critical functions and determine RTO/RPO.

Cloud Platform and Infrastructure Security

Memory trick

BCDR & Cloud Security Posture Management

To remember BCDR strategies: 'B P W H' - 'Big Problems? We're Here!' (Backup, Pilot light, Warm, Hot). Each one gets faster and more expensive!

Cloud Platform and Infrastructure Security

Exam tip

BCDR & Cloud Security Posture Management

The exam frequently tests your understanding of RTO and RPO, and how different BCDR strategies (backup & restore, pilot light, warm standby, hot standby) align with these objectives. Memorize the relative costs and recovery times for each strategy. Also, understand the core function of CSPM: continuous monitoring for misconfigurations and compliance.

Cloud Platform and Infrastructure Security

Common mistake

BCDR & Cloud Security Posture Management

Confusing RTO with RPO; RTO is about time to recover, RPO is about data loss.

Cloud Platform and Infrastructure Security

Common mistake

BCDR & Cloud Security Posture Management

Assuming the cloud provider handles all BCDR; remember the shared responsibility model.

Cloud Platform and Infrastructure Security

Common mistake

BCDR & Cloud Security Posture Management

Failing to regularly test BCDR plans, leading to unexpected failures during actual disasters.

Cloud Platform and Infrastructure Security

Key term

SSDLC

Secure Software Development Lifecycle, integrating security into every phase.

Cloud Application Security

Key term

Shift Left

Integrating security activities as early as possible in the development process.

Cloud Application Security

Key term

Threat Modeling

Structured approach to identify potential threats and vulnerabilities in a system.

Cloud Application Security

Key term

SAST

Static Application Security Testing, analyzing source code without execution.

Cloud Application Security

Key term

DAST

Dynamic Application Security Testing, analyzing running applications for vulnerabilities.

Cloud Application Security

Key term

DevSecOps

Integrating security practices into DevOps processes, emphasizing automation.

Cloud Application Security

Key term

IaC

Infrastructure as Code, managing and provisioning infrastructure through code.

Cloud Application Security

Key term

Immutable Infrastructure

Servers are never modified after deployment; new versions replace old ones.

Cloud Application Security

Memory trick

Cloud Application Development Lifecycle

Remember the SSDLC phases with: 'Really Design It To Deploy More.' (Requirements, Design, Implementation, Testing, Deployment, Maintenance)

Cloud Application Security

Exam tip

Cloud Application Development Lifecycle

The exam often tests your understanding of *when* specific security activities occur in the SSDLC. Keywords like 'requirements gathering,' 'design review,' 'code commit,' or 'pre-deployment' should trigger associations with the appropriate security tasks (e.g., threat modeling, architecture review, SAST, penetration testing).

Cloud Application Security

Common mistake

Cloud Application Development Lifecycle

Treating security as a separate phase at the end of development, leading to costly last-minute fixes.

Cloud Application Security

Common mistake

Cloud Application Development Lifecycle

Failing to adapt SSDLC practices for cloud-native environments, ignoring unique challenges like microservices and serverless.

Cloud Application Security

Common mistake

Cloud Application Development Lifecycle

Over-relying on automated tools without understanding their limitations or performing manual security reviews.

Cloud Application Security

Key term

Parameterized Queries

Technique to prevent SQL injection by separating code from data.

Cloud Application Security

Key term

API Gateway

Service that acts as a single entry point for a group of APIs.

Cloud Application Security

Key term

Infrastructure as Code (IaC)

Managing and provisioning infrastructure through code instead of manual processes.

Cloud Application Security

Memory trick

Cloud Application Security Best Practices

Think 'SECURE APPS': **S**ecure Design, **E**ncryption, **C**onfiguration, **U**ser Access, **R**esponse Plan, **E**valuate Regularly, **A**PI Security, **P**rivacy, **P**atching, **S**ecure Coding.

Cloud Application Security

Exam tip

Cloud Application Security Best Practices

The exam frequently tests on the 'shared responsibility model' in the context of application security. Remember that while the cloud provider secures the 'cloud itself,' the customer is responsible for security 'in the cloud,' which includes applications, data, configurations, and access controls.

Cloud Application Security

Common mistake

Cloud Application Security Best Practices

Assuming the cloud provider secures your application code and data by default.

Cloud Application Security

Common mistake

Cloud Application Security Best Practices

Neglecting regular security patching and updates for application components.

Cloud Application Security

Common mistake

Cloud Application Security Best Practices

Not performing input validation, leading to common vulnerabilities like SQL injection or XSS.

Cloud Application Security

Key term

RBAC

Role-Based Access Control; permissions assigned to roles.

Cloud Application Security

Key term

ABAC

Attribute-Based Access Control; granular permissions based on attributes.

Cloud Application Security

Key term

Federated Identity

Single sign-on across multiple security domains.

Cloud Application Security

Key term

OAuth 2.0

Authorization framework for delegated access.

Cloud Application Security

Key term

JWT

JSON Web Token; secure, compact, URL-safe claims representation.

Cloud Application Security

Memory trick

IAM for Cloud Apps & API Security

For API Security, remember 'A.G.E.S.': Authentication, Gateway, Encryption, input Validation, and Scopes (for authorization).

Cloud Application Security

Exam tip

IAM for Cloud Apps & API Security

The exam frequently tests on the differences and appropriate use cases for RBAC vs. ABAC. Remember that ABAC offers more granular, dynamic control based on real-time attributes, while RBAC is simpler and role-centric. Also, be familiar with the core components and benefits of an API Gateway.

Cloud Application Security

Common mistake

IAM for Cloud Apps & API Security

Relying solely on API keys for authentication without additional security measures.

Cloud Application Security

Common mistake

IAM for Cloud Apps & API Security

Granting overly broad permissions to cloud applications or APIs (violating least privilege).

Cloud Application Security

Common mistake

IAM for Cloud Apps & API Security

Neglecting input validation on API endpoints, leading to injection vulnerabilities.

Cloud Application Security

Key term

Shift-Left

Moving security activities and testing to earlier stages of the SDLC.

Cloud Application Security

Key term

CI/CD Pipeline

Automated process for building, testing, and deploying software.

Cloud Application Security

Key term

SCA

Software Composition Analysis; identifies vulnerabilities in open-source components.

Cloud Application Security

Key term

IaC Security Scanning

Automated analysis of infrastructure as code for security misconfigurations.

Cloud Application Security

Key term

CSPM

Cloud Security Posture Management; monitors cloud environments for misconfigurations.

Cloud Application Security

Memory trick

DevSecOps in the Cloud

SECURE Code: Scan Early, Continuously Update, Review Everything.

Cloud Application Security

Exam tip

DevSecOps in the Cloud

The exam often tests the 'shift-left' concept and the integration of specific security tools (SAST, DAST, SCA, IaC scanning) at different stages of the CI/CD pipeline. Memorize which tool applies to which stage and its purpose.

Cloud Application Security

Common mistake

DevSecOps in the Cloud

Treating security as a separate team's responsibility rather than a shared one.

Cloud Application Security

Common mistake

DevSecOps in the Cloud

Only performing security testing at the very end of the development cycle.

Cloud Application Security

Common mistake

DevSecOps in the Cloud

Failing to automate security checks, leading to manual bottlenecks and inconsistencies.

Cloud Application Security

Key term

Security Baseline

Minimum security configuration for systems and services.

Cloud Security Operations

Key term

Configuration Management

Process of maintaining system configurations to a desired state.

Cloud Security Operations

Key term

Configuration Drift

Systems diverging from their intended secure configuration over time.

Cloud Security Operations

Key term

Shift-Left Security

Integrating security practices earlier in the development lifecycle.

Cloud Security Operations

Memory trick

Implementing & Managing Cloud Security Operations

To remember the operational cycle, think 'BPM-DRU': Baselines, Provisioning, Monitor, Detect, Remediate, Update. It's a continuous loop!

Cloud Security Operations

Exam tip

Implementing & Managing Cloud Security Operations

The exam often tests your understanding of the shared responsibility model in the context of operational tasks. Remember that while cloud providers secure the cloud, you are responsible for security in the cloud, including configuration management, identity management, and data protection. Keywords like 'configuration drift,' 'IaC,' and 'CSPM' are critical.

Cloud Security Operations

Common mistake

Implementing & Managing Cloud Security Operations

Failing to automate security checks, leading to manual errors and inconsistent security.

Cloud Security Operations

Common mistake

Implementing & Managing Cloud Security Operations

Neglecting to regularly review and update security baselines as threats and technologies evolve.

Cloud Security Operations

Common mistake

Implementing & Managing Cloud Security Operations

Treating cloud security as a one-time setup rather than a continuous operational process.

Cloud Security Operations

Key term

Incident Response (IR)

Structured approach to managing security incidents.

Cloud Security Operations

Key term

SIEM

Aggregates security data for analysis and alerting.

Cloud Security Operations

Key term

Ephemeral Resources

Cloud resources with short, dynamic lifespans.

Cloud Security Operations

Key term

Playbook

Pre-defined steps for responding to specific incidents.

Cloud Security Operations

Key term

CloudTrail

AWS service for logging API calls and events.

Cloud Security Operations

Key term

Containment

Limiting the scope and impact of an incident.

Cloud Security Operations

Memory trick

Incident Response & SIEM in the Cloud

P-D-C-E-R-P: Prepare, Detect, Contain, Eradicate, Recover, Post-incident. It's like a police investigation: Plan, Discover, Cordon, Eliminate, Restore, Post-mortem.

Cloud Security Operations

Exam tip

Incident Response & SIEM in the Cloud

The CCSP exam frequently tests your understanding of the shared responsibility model in the context of incident response. Memorize which party (customer or CSP) is responsible for which layers of the stack and how that impacts IR actions. Keywords to spot include 'who is responsible for...', 'customer's duty', 'CSP's obligation'.

Cloud Security Operations

Common mistake

Incident Response & SIEM in the Cloud

Assuming the CSP is responsible for all security incidents, neglecting customer's duties.

Cloud Security Operations

Common mistake

Incident Response & SIEM in the Cloud

Failing to integrate cloud-native logs into a centralized SIEM for comprehensive visibility.

Cloud Security Operations

Common mistake

Incident Response & SIEM in the Cloud

Not having automated response actions or playbooks for common cloud incident types.

Cloud Security Operations

Key term

Cloud Forensics

Application of digital forensics to cloud environments for evidence.

Cloud Security Operations

Key term

Chain of Custody

Documented chronological history of evidence handling.

Cloud Security Operations

Key term

Data Volatility

The tendency of data to change or disappear quickly.

Cloud Security Operations

Key term

Security Audit

Systematic evaluation of security controls and compliance.

Cloud Security Operations

Key term

eDiscovery

Process of identifying and producing electronic information for legal cases.

Cloud Security Operations

Memory trick

Cloud Forensics & Security Auditing

To remember the forensics process, think: 'I Really Can't Analyze Really Random data.' (Incident, Response, Collection, Analysis, Reporting, Recovery)

Cloud Security Operations

Exam tip

Cloud Forensics & Security Auditing

The exam often tests your understanding of the differences between traditional and cloud forensics, specifically regarding evidence acquisition and chain of custody. Memorize that direct physical access to hardware is typically NOT available in cloud forensics.

Cloud Security Operations

Common mistake

Cloud Forensics & Security Auditing

Assuming you have the same level of access to evidence in the cloud as in an on-premise environment.

Cloud Security Operations

Common mistake

Cloud Forensics & Security Auditing

Failing to establish clear communication channels and SLAs with the CSP for forensic support.

Cloud Security Operations

Common mistake

Cloud Forensics & Security Auditing

Neglecting legal and jurisdictional implications when planning cloud forensic investigations.

Cloud Security Operations

Key term

Continuous Monitoring

Ongoing observation of cloud resources for security events.

Cloud Security Operations

Key term

CWPP

Cloud Workload Protection Platform; secures workloads across cloud environments.

Cloud Security Operations

Key term

Vulnerability Scanning

Automated process to identify known security weaknesses.

Cloud Security Operations

Key term

Penetration Testing

Simulated attack to find exploitable vulnerabilities in systems.

Cloud Security Operations

Key term

Cloud Audit

Independent examination of cloud security controls and compliance.

Cloud Security Operations

Key term

Baseline

A known good configuration or normal operational state.

Cloud Security Operations

Key term

Anomaly Detection

Identifying deviations from established normal patterns or baselines.

Cloud Security Operations

Memory trick

Cloud Security Monitoring & Assessment

MONITOR: M-Metrics, O-Observe, N-Notify, I-Investigate, T-Test, O-Optimize, R-Report. It's a continuous loop!

Cloud Security Operations

Exam tip

Cloud Security Monitoring & Assessment

The CCSP exam frequently tests the distinction between continuous monitoring (ongoing, real-time) and periodic assessments (scheduled, in-depth). Know the purpose of CSPM vs. CWPP and how they contribute to overall security posture.

Cloud Security Operations

Common mistake

Cloud Security Monitoring & Assessment

Relying solely on cloud provider native tools without considering third-party solutions for multi-cloud or advanced needs.

Cloud Security Operations

Common mistake

Cloud Security Monitoring & Assessment

Failing to establish security baselines, making it difficult to identify actual anomalies versus normal activity.

Cloud Security Operations

Common mistake

Cloud Security Monitoring & Assessment

Treating security assessments as a one-time event rather than an ongoing, iterative process.

Cloud Security Operations

Key term

Jurisdiction

Legal authority over a territory or case.

Legal, Risk, and Compliance in the Cloud

Key term

Data Sovereignty

Data subject to laws of its physical location.

Legal, Risk, and Compliance in the Cloud

Key term

GDPR

EU regulation for data protection and privacy.

Legal, Risk, and Compliance in the Cloud

Key term

HIPAA

US law protecting health information privacy.

Legal, Risk, and Compliance in the Cloud

Key term

CCPA/CPRA

California laws for consumer privacy rights.

Legal, Risk, and Compliance in the Cloud

Key term

Privacy by Design

Embedding privacy into system architecture.

Legal, Risk, and Compliance in the Cloud

Key term

Right to Erasure

Individual's right to have personal data deleted.

Legal, Risk, and Compliance in the Cloud

Key term

Standard Contractual Clauses

Legal safeguards for cross-border data transfers.

Legal, Risk, and Compliance in the Cloud

Memory trick

Legal Requirements, Issues & Privacy

J.U.R.I.S.D.I.C.T.I.O.N. - Just Understand Regulations In Several Different International Countries' Territories Is Our Necessity.

Legal, Risk, and Compliance in the Cloud

Exam tip

Legal Requirements, Issues & Privacy

The CCSP exam frequently tests your understanding of jurisdiction and data residency. Remember that the physical location of data, not just the company's HQ, determines applicable laws. Watch for questions about GDPR's extraterritorial reach and the implications of storing data in different countries.

Legal, Risk, and Compliance in the Cloud

Common mistake

Legal Requirements, Issues & Privacy

Assuming all cloud providers handle data privacy the same way; contracts vary significantly.

Legal, Risk, and Compliance in the Cloud

Common mistake

Legal Requirements, Issues & Privacy

Ignoring the physical location of data centers, believing only the company's HQ jurisdiction applies.

Legal, Risk, and Compliance in the Cloud

Common mistake

Legal Requirements, Issues & Privacy

Underestimating the complexity and potential penalties of non-compliance with global privacy regulations.

Legal, Risk, and Compliance in the Cloud

Key term

Cloud Governance

Framework of policies ensuring cloud usage aligns with business objectives.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Avoidance

Eliminating the activity that carries the identified risk.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Transfer

Shifting risk responsibility or financial burden to another party.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Mitigation

Reducing the likelihood or impact of a risk through controls.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Acceptance

Acknowledging a risk and deciding not to take action.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Assessment

Process of identifying, analyzing, and evaluating risks.

Legal, Risk, and Compliance in the Cloud

Key term

Risk Register

Document that lists and prioritizes identified risks.

Legal, Risk, and Compliance in the Cloud

Memory trick

Audit Process, Governance & Risk Management

For risk strategies, remember 'ATMA': Avoid, Transfer, Mitigate, Accept. It's the 'ATM for your risks' – you either take money out (avoid/mitigate) or put it in (transfer/accept).

Legal, Risk, and Compliance in the Cloud

Exam tip

Audit Process, Governance & Risk Management

The exam often tests the distinct phases of an audit and the different risk treatment strategies. Keywords like 'planning,' 'fieldwork,' 'reporting,' 'follow-up' for audits, and 'avoid,' 'transfer,' 'mitigate,' 'accept' for risk treatment are critical to recognize.

Legal, Risk, and Compliance in the Cloud

Common mistake

Audit Process, Governance & Risk Management

Confusing the phases of an audit with the phases of a risk management cycle.

Legal, Risk, and Compliance in the Cloud

Common mistake

Audit Process, Governance & Risk Management

Applying a 'one-size-fits-all' risk treatment strategy instead of tailoring it to specific risks.

Legal, Risk, and Compliance in the Cloud

Common mistake

Audit Process, Governance & Risk Management

Failing to recognize that governance is an ongoing process, not a one-time setup.

Legal, Risk, and Compliance in the Cloud

Key term

Compliance

Adherence to rules, laws, standards, and policies.

Legal, Risk, and Compliance in the Cloud

Key term

Cloud Service Agreement (CSA)

Legal contract between a CSP and a customer.

Legal, Risk, and Compliance in the Cloud

Key term

Service Level Agreement (SLA)

Contractual guarantee of service performance and availability.

Legal, Risk, and Compliance in the Cloud

Key term

Data Processing Addendum (DPA)

Contractual terms for handling personal data under privacy laws.

Legal, Risk, and Compliance in the Cloud

Key term

Regulatory Compliance

Adherence to government laws and regulations.

Legal, Risk, and Compliance in the Cloud

Key term

Industry Compliance

Adherence to specific industry standards.

Legal, Risk, and Compliance in the Cloud

Memory trick

Compliance & Cloud Service Agreements

CSA: 'C'ompliance 'S'ecurity 'A'greement – it's all about making sure your cloud is secure and compliant through agreements!

Legal, Risk, and Compliance in the Cloud

Exam tip

Compliance & Cloud Service Agreements

The exam often tests your understanding of the shared responsibility model and how compliance obligations are divided. Pay close attention to who is responsible for 'of the cloud' versus 'in the cloud' when evaluating CSA clauses.

Legal, Risk, and Compliance in the Cloud

Common mistake

Compliance & Cloud Service Agreements

Assuming the CSP is solely responsible for all compliance in the cloud.

Legal, Risk, and Compliance in the Cloud

Common mistake

Compliance & Cloud Service Agreements

Not thoroughly reviewing the CSA, especially data residency and audit clauses.

Legal, Risk, and Compliance in the Cloud

Common mistake

Compliance & Cloud Service Agreements

Failing to negotiate specific compliance requirements into the CSA.

Legal, Risk, and Compliance in the Cloud

Key term

Supply Chain Risk Management

Managing risks associated with external entities providing goods or services.

Legal, Risk, and Compliance in the Cloud

Key term

Third-Party Risk Management (TPRM)

Systematic process for identifying, assessing, and mitigating vendor risks.

Legal, Risk, and Compliance in the Cloud

Key term

Enterprise Risk Management (ERM)

Holistic framework for identifying, assessing, and responding to all organizational risks.

Legal, Risk, and Compliance in the Cloud

Key term

Cloud Supply Chain

All entities involved in delivering a cloud service, direct and indirect.

Legal, Risk, and Compliance in the Cloud

Key term

Due Diligence

Investigation performed to assess the risks of a business transaction.

Legal, Risk, and Compliance in the Cloud

Memory trick

Supply Chain Management & ERM

To remember the key steps of TPRM: 'VENDORS' – Validate, Evaluate, Negotiate, Document, Observe, Respond, Secure.

Legal, Risk, and Compliance in the Cloud

Exam tip

Supply Chain Management & ERM

The exam often tests your understanding of 'shared responsibility model' implications for supply chain. Remember that while the CSP handles 'security of the cloud,' you are still responsible for 'security in the cloud,' which includes managing risks introduced by your chosen third-party providers and their sub-processors.

Legal, Risk, and Compliance in the Cloud

Common mistake

Supply Chain Management & ERM

Assuming your CSP's security covers all third-party risks; you must manage your own third-party relationships.

Legal, Risk, and Compliance in the Cloud

Common mistake

Supply Chain Management & ERM

Neglecting to include specific security and audit clauses in contracts with cloud vendors and their sub-processors.

Legal, Risk, and Compliance in the Cloud

Common mistake

Supply Chain Management & ERM

Treating third-party risk management as a one-time activity rather than continuous monitoring and review.

Legal, Risk, and Compliance in the Cloud