Step2Study
IT & TechnologyPCCET100% Free

Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)

Practice bank
209 Qs
Real exam
75 Qs
Time limit
90 min
Passing
The passing score is not published by Palo Alto Networks.

Exam blueprint

Cybersecurity Fundamentals
25%
Network Security
25%
Cloud Security
20%
Security Operations
20%
Palo Alto Networks Technologies
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 108 min · pass 70% · 209 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) practice test questions

Sample questions from the 209-question bank, with answers and explanations.

All questions
  1. 1. A cloud administrator is configuring access to a shared object storage bucket containing sensitive customer data. They need to ensure that different teams within the organization have varying levels of access (e.g., read-only for analytics, read-write for application developers, no access for general users). Which cloud security component is primarily responsible for defining and enforcing these fine-grained permissions?

    Cloud Security

    • A. Network Access Control List (NACL)
    • B. Identity and Access Management (IAM)
    • C. Cloud Logging and Monitoring
    • D. Virtual Private Cloud (VPC)
    Show answer

    B. Identity and Access Management (IAM)

    Identity and Access Management (IAM) is the primary service in cloud environments responsible for managing users, groups, roles, and their associated permissions, allowing administrators to define and enforce fine-grained access control to resources like object storage buckets.

  2. 2. An organization is migrating its legacy applications to a cloud environment. They are concerned about the security implications of 'shadow IT' where employees use unauthorized cloud services for business purposes. Which cloud security best practice primarily helps to gain visibility and control over such unsanctioned cloud usage?

    Cloud Security

    • A. Implementing a Cloud Access Security Broker (CASB) solution.
    • B. Conducting regular penetration testing of cloud-hosted applications.
    • C. Ensuring all cloud resources are tagged appropriately for cost allocation.
    • D. Implementing strong multi-factor authentication (MFA) for all cloud accounts.
    Show answer

    A. Implementing a Cloud Access Security Broker (CASB) solution.

    Shadow IT is a key challenge that CASBs are designed to address. CASBs can discover and monitor cloud services, sanctioned or unsanctioned, providing visibility into usage, user activity, and data flowing to and from these services, allowing organizations to enforce security policies and mitigate risks associated with shadow IT.

  3. 3. A cybersecurity team is performing a penetration test against a cloud-native application. During their reconnaissance phase, they discover that one of the application's API endpoints is vulnerable to SQL injection and cross-site scripting (XSS) attacks. To mitigate these specific threats at the edge of the network before they reach the application, which cloud security technology should the team recommend?

    Cloud Security

    • A. Cloud Security Posture Management (CSPM)
    • B. Cloud Workload Protection Platform (CWPP)
    • C. Web Application Firewall (WAF)
    • D. Network Access Control List (NACL)
    Show answer

    C. Web Application Firewall (WAF)

    A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS by filtering HTTP/S traffic at the application layer (Layer 7) before it reaches the application server, making it ideal for mitigating these threats at the network edge.

  4. 4. A company is implementing a cloud-native security solution to protect its containerized applications running on a Kubernetes cluster. The solution needs to provide vulnerability scanning for container images, runtime protection for running containers, and network segmentation for container traffic. What type of cloud security technology consolidates these capabilities?

    Cloud Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Cloud Access Security Broker (CASB)
    • C. Cloud Security Posture Management (CSPM)
    • D. Security Information and Event Management (SIEM)
    Show answer

    A. Cloud Workload Protection Platform (CWPP)

    A Cloud Workload Protection Platform (CWPP) is designed to secure workloads like containers, virtual machines, and serverless functions across hybrid and multi-cloud environments, offering features such as vulnerability management, runtime protection, and network segmentation specifically for these workloads.

  5. 5. A cloud security team is concerned about the potential for unmanaged and unsanctioned cloud services being used by employees without IT oversight. This practice can introduce significant security risks and compliance gaps. What is this phenomenon commonly referred to, and what is a primary concern for the security team?

    Cloud Security

    • A. Cloud Sprawl, leading to excessive resource consumption.
    • B. Data Residency, leading to legal and regulatory complications.
    • C. Vendor Lock-in, leading to difficulty in switching cloud providers.
    • D. Shadow IT, leading to unmanaged security risks and compliance issues.
    Show answer

    D. Shadow IT, leading to unmanaged security risks and compliance issues.

    The use of unmanaged and unsanctioned cloud services by employees is known as Shadow IT. The primary concern for the security team is the introduction of unmanaged security risks and potential compliance violations because these services are not under IT's control.

  6. 6. A cloud architect is designing a new application that will process sensitive customer data. They need to ensure that the application's runtime environment is isolated from other tenants and provides a dedicated, single-tenant infrastructure. Which cloud deployment model would best meet this requirement?

    Cloud Security

    • A. Hybrid Cloud
    • B. Community Cloud
    • C. Private Cloud
    • D. Public Cloud
    Show answer

    C. Private Cloud

    A private cloud offers a dedicated, single-tenant environment, which provides the highest level of isolation and control, making it suitable for sensitive data applications. This directly addresses the requirement for isolated runtime and dedicated infrastructure.

  7. 7. A cybersecurity analyst is investigating an incident where unauthorized access to a cloud-based database occurred. The investigation reveals that the database was configured with overly permissive access policies, allowing external users to read and write data without proper authentication. Which security principle was most likely violated?

    Cloud Security

    • A. Data Redundancy
    • B. High Availability
    • C. Elasticity
    • D. Least Privilege
    Show answer

    D. Least Privilege

    The principle of Least Privilege dictates that users and systems should only be granted the minimum necessary permissions to perform their tasks. Overly permissive access policies directly violate this principle, leading to potential unauthorized access.

  8. 8. A development team is implementing a serverless application using AWS Lambda. They want to ensure that the Lambda functions can only access the specific AWS S3 buckets required for their operation and nothing else. Which AWS security best practice should they implement to achieve this granular access control?

    Cloud Security

    • A. Implement client-side encryption for all data stored in the S3 buckets.
    • B. Apply a strict Network Access Control List (NACL) to the VPC containing the Lambda function.
    • C. Attach an IAM policy with the principle of least privilege to the Lambda execution role.
    • D. Configure an AWS WAF to block unauthorized S3 access attempts.
    Show answer

    C. Attach an IAM policy with the principle of least privilege to the Lambda execution role.

    IAM policies are the primary mechanism for controlling access to AWS resources. By attaching a finely-tuned IAM policy to the Lambda function's execution role, the principle of least privilege can be enforced, granting access only to the specific S3 buckets and actions required.

  9. 9. A security team is implementing a solution to continuously monitor the security posture of their cloud resources, identify misconfigurations, and ensure compliance with industry standards. What type of cloud security technology would best meet these requirements?

    Cloud Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Cloud Security Posture Management (CSPM)
    • C. Distributed Denial of Service (DDoS) protection
    • D. Cloud Access Security Broker (CASB)
    Show answer

    B. Cloud Security Posture Management (CSPM)

    Cloud Security Posture Management (CSPM) solutions are specifically designed to continuously monitor cloud environments for misconfigurations, compliance deviations, and security risks, providing visibility and remediation recommendations.

  10. 10. A cybersecurity team is concerned about the risk of 'shadow IT' within their organization, where employees are using unapproved cloud services for business operations. Which cloud security best practice is most effective in mitigating this risk?

    Cloud Security

    • A. Implementing strong data encryption at rest
    • B. Conducting regular penetration testing
    • C. Enforcing the Principle of Least Privilege
    • D. Establishing a robust Cloud Access Security Broker (CASB)
    Show answer

    D. Establishing a robust Cloud Access Security Broker (CASB)

    A Cloud Access Security Broker (CASB) provides visibility into cloud service usage, including unapproved 'shadow IT' applications, and can enforce security policies, block access to unsanctioned apps, and prevent data exfiltration, directly addressing the risks of shadow IT.

  11. 11. A cloud architect is designing a new application that requires high availability and disaster recovery across multiple geographical regions. Which cloud deployment model would best support these requirements?

    Cloud Security

    • A. Public cloud
    • B. Hybrid cloud
    • C. Private cloud
    • D. Community cloud
    Show answer

    A. Public cloud

    Public clouds offer a globally distributed infrastructure with multiple regions and availability zones, inherently supporting high availability and disaster recovery across diverse geographical locations.

  12. 12. A security architect is designing a secure cloud environment. They want to ensure that all network traffic entering and exiting their Virtual Private Cloud (VPC) is inspected and filtered based on defined rules. Which cloud security technology is best suited for this purpose at the perimeter of the VPC?

    Cloud Security

    • A. Network Access Control Lists (NACLs)
    • B. Web Application Firewall (WAF)
    • C. Identity and Access Management (IAM)
    • D. Security Groups
    Show answer

    A. Network Access Control Lists (NACLs)

    NACLs are stateless packet filters that operate at the subnet level within a VPC. They allow or deny traffic based on IP addresses, ports, and protocols, acting as a virtual firewall for inbound and outbound traffic for an entire subnet.

  13. 13. A cloud security engineer needs to implement a solution that continuously monitors their cloud resources for security misconfigurations and compliance violations against industry benchmarks and regulatory standards. Which type of cloud security technology is specifically designed for this purpose?

    Cloud Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Cloud Security Posture Management (CSPM)
    • C. Security Information and Event Management (SIEM)
    • D. Cloud Access Security Broker (CASB)
    Show answer

    B. Cloud Security Posture Management (CSPM)

    CSPM tools continuously monitor cloud environments for security misconfigurations, compliance violations, and risks. They help organizations maintain a strong security posture by identifying and often remediating issues against defined policies and regulatory frameworks.

  14. 14. A development team is using microservices architecture deployed on containers in a public cloud. They want a security solution that can protect these containerized applications throughout their lifecycle, from image scanning to runtime protection, and integrate with their CI/CD pipeline. Which cloud security technology is specifically designed for this purpose?

    Cloud Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Data Loss Prevention (DLP)
    • C. Cloud Access Security Broker (CASB)
    • D. Cloud Security Posture Management (CSPM)
    Show answer

    A. Cloud Workload Protection Platform (CWPP)

    A CWPP is specifically designed to secure cloud workloads, including containers and microservices, throughout their lifecycle. It provides capabilities like vulnerability scanning of container images, runtime protection, and integration with CI/CD for continuous security.

  15. 15. A cloud security engineer is tasked with ensuring that all sensitive data stored in their object storage service is protected against unauthorized viewing, even if an attacker gains access to the storage infrastructure itself. This protection must apply to data that is not actively being transferred. Which security best practice is being addressed?

    Cloud Security

    • A. Multi-factor authentication (MFA)
    • B. Data in transit encryption
    • C. Data at rest encryption
    • D. Network segmentation
    Show answer

    C. Data at rest encryption

    Data at rest encryption protects data while it is stored on a persistent medium, rendering it unreadable without the correct decryption key, even if the storage infrastructure is compromised. This directly addresses protection for data 'not actively being transferred'.

  16. 16. Which cloud service model provides consumers with access to infrastructure resources such as virtual machines, storage, and networks, but requires them to manage the operating system and applications?

    Cloud Security

    • A. Function as a Service (FaaS)
    • B. Software as a Service (SaaS)
    • C. Platform as a Service (PaaS)
    • D. Infrastructure as a Service (IaaS)
    Show answer

    D. Infrastructure as a Service (IaaS)

    IaaS provides the foundational computing resources, giving users control over operating systems, applications, and middleware. The cloud provider manages the underlying hardware and virtualization.

  17. 17. A company is migrating its on-premises data center to a public cloud environment. They are concerned about maintaining a consistent security policy across both environments and ensuring that sensitive data transmitted between their on-premises network and the cloud is protected. Which cloud security best practice should they prioritize to address these concerns?

    Cloud Security

    • A. Establishing secure network connectivity, such as VPNs or direct connect services, between on-premises and cloud.
    • B. Implementing a robust Data Loss Prevention (DLP) solution within the cloud environment only.
    • C. Encrypting all data at rest within the cloud, but not focusing on data in transit.
    • D. Relying solely on the cloud provider's default security settings for data in transit.
    Show answer

    A. Establishing secure network connectivity, such as VPNs or direct connect services, between on-premises and cloud.

    Establishing secure network connectivity like VPNs or direct connect services is crucial for protecting data in transit between on-premises and cloud environments and for extending consistent security policies across the hybrid boundary.

  18. 18. A cloud security engineer discovers that several Amazon S3 buckets containing sensitive company data are publicly accessible. This misconfiguration poses a significant data breach risk. What is the immediate and most critical best practice to apply to these S3 buckets?

    Cloud Security

    • A. Configure cross-region replication.
    • B. Enable versioning on the buckets.
    • C. Enable server-side encryption with customer-provided keys.
    • D. Restrict public access to the buckets.
    Show answer

    D. Restrict public access to the buckets.

    The most critical immediate action for publicly accessible sensitive S3 buckets is to restrict public access. This directly mitigates the data breach risk by preventing unauthorized external users from accessing the data.

  19. 19. A cybersecurity team is concerned about the risk of 'shadow IT' within their organization, specifically employees using unsanctioned cloud applications to store and share company data. They need a solution that can discover these unsanctioned applications, assess their risk, enforce security policies, and detect sensitive data exfiltration to them. Which cloud security technology is designed for this purpose?

    Cloud Security

    • A. Cloud Security Posture Management (CSPM)
    • B. Cloud Workload Protection Platform (CWPP)
    • C. Network Intrusion Detection System (NIDS)
    • D. Cloud Access Security Broker (CASB)
    Show answer

    D. Cloud Access Security Broker (CASB)

    A Cloud Access Security Broker (CASB) is specifically designed to address shadow IT by discovering unsanctioned cloud applications, monitoring user activity, enforcing security policies, and preventing sensitive data from being uploaded to or downloaded from these services.

  20. 20. A cloud security engineer is implementing a solution to continuously monitor the security posture of their cloud resources, identify misconfigurations, and ensure compliance with regulatory standards. They need a tool that can provide visibility into their entire cloud environment and suggest remediation steps. Which cloud security technology would be most appropriate for this task?

    Cloud Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Cloud Access Security Broker (CASB)
    • C. Web Application Firewall (WAF)
    • D. Cloud Security Posture Management (CSPM)
    Show answer

    D. Cloud Security Posture Management (CSPM)

    CSPM solutions are specifically designed to continuously monitor cloud environments for misconfigurations, compliance deviations, and security risks, providing visibility and recommending remediation, directly matching the engineer's requirements.

  21. 21. A security analyst is investigating an incident where unauthorized access to a cloud-based application occurred. The investigation reveals that the application's API keys were hardcoded into a public code repository. Which cloud security best practice was violated?

    Cloud Security

    • A. Secure Software Development Lifecycle (SSDLC)
    • B. Data Encryption at Rest
    • C. Principle of Least Privilege
    • D. Regular Security Audits
    Show answer

    A. Secure Software Development Lifecycle (SSDLC)

    Hardcoding API keys into a public repository is a critical flaw in the secure software development lifecycle (SSDLC), specifically in the 'secure coding' phase, as it exposes sensitive credentials during development and deployment.

  22. 22. A cloud security architect is designing a highly secure environment for a financial services application. They need to ensure that the application's network traffic is inspected and filtered at the application layer (Layer 7) for malicious content, such as SQL injection attempts or cross-site scripting (XSS). Which security technology is best suited for this specific task?

    Cloud Security

    • A. Stateful Firewall
    • B. Web Application Firewall (WAF)
    • C. Network Access Control List (NACL)
    • D. Security Group
    Show answer

    B. Web Application Firewall (WAF)

    A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks by filtering and monitoring HTTP traffic at Layer 7, detecting and blocking threats like SQL injection and XSS.

  23. 23. A cloud security team is tasked with ensuring that all sensitive data stored in their cloud object storage is encrypted both at rest and in transit. They have already implemented server-side encryption for data at rest. What additional measure should they take to secure data in transit when accessed by applications?

    Cloud Security

    • A. Enable multi-factor authentication (MFA) for all object storage access.
    • B. Ensure all client applications use HTTPS/TLS for communication.
    • C. Utilize Identity and Access Management (IAM) policies to restrict access.
    • D. Configure Network Access Control Lists (NACLs) to block unencrypted traffic.
    Show answer

    B. Ensure all client applications use HTTPS/TLS for communication.

    HTTPS (HTTP Secure), which uses TLS (Transport Layer Security) encryption, is the standard and most effective method for encrypting data in transit over networks, including when accessing cloud object storage. This ensures confidentiality and integrity of data as it moves between client applications and the cloud service.

  24. 24. A multinational corporation is adopting a hybrid cloud strategy, utilizing both their on-premises Active Directory and cloud-based applications. They want to ensure that employees can use their existing corporate credentials to access cloud applications without re-entering them. Which security concept is crucial for achieving this seamless access?

    Cloud Security

    • A. Federated Identity Management
    • B. Cloud Security Posture Management (CSPM)
    • C. Role-Based Access Control (RBAC)
    • D. Multi-Factor Authentication (MFA)
    Show answer

    A. Federated Identity Management

    Federated Identity Management allows users to authenticate once with a single identity provider (like on-premises Active Directory) and gain access to multiple services and applications, including those in the cloud, without needing separate credentials.

  25. 25. A cloud architect is designing a new application that will process sensitive customer data and requires strict control over the underlying infrastructure, including hardware and network configurations. Which cloud service model offers the most control over these aspects?

    Cloud Security

    • A. Software as a Service (SaaS)
    • B. Infrastructure as a Service (IaaS)
    • C. Function as a Service (FaaS)
    • D. Platform as a Service (PaaS)
    Show answer

    B. Infrastructure as a Service (IaaS)

    Infrastructure as a Service (IaaS) provides the highest level of control over the underlying infrastructure, including virtual machines, storage, and networking components, allowing the architect to manage hardware and network configurations directly.

Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) flashcards

Tap a card to flip it. 136 flashcards in the full deck.

  • Identity and Access Management (IAM)

    Flip card

    A framework of policies and technologies that controls who can access what resources under which circumstances in a cloud environment.

    • Manages users, groups, and roles
    • Defines granular permissions to cloud resources
    • Crucial for enforcing the principle of least privilege
    Study this card →
  • Shadow IT Mitigation

    Flip card

    Shadow IT refers to the use of IT systems, devices, software, applications, and services without explicit organizational approval. Mitigating it involves gaining visibility and control over all cloud services used by employees.

    • CASBs are primary tools for discovering and managing shadow IT.
    • Shadow IT poses risks like data leakage, compliance violations, and security vulnerabilities.
    • Visibility and policy enforcement are key to mitigation.
    Study this card →
  • Web Application Firewall (WAF)

    Flip card

    A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against common web-based attacks like SQL injection and XSS.

    • Operates at the application layer (Layer 7)
    • Protects against specific web exploits
    • Deployed at the edge of the network
    Study this card →
  • Cloud Workload Protection Platform (CWPP)

    Flip card

    A security solution that provides comprehensive protection for server workloads (virtual machines, containers, and serverless functions) across hybrid and multi-cloud environments, covering vulnerability management, runtime protection, and network segmentation.

    • Secures workloads throughout their lifecycle.
    • Includes vulnerability scanning, malware detection, behavioral monitoring.
    • Supports various workload types like containers and VMs.
    Study this card →
  • Shadow IT

    Flip card

    The use of IT systems, devices, software, applications, and services without explicit organizational approval or oversight from the IT department.

    • Introduces unmanaged security risks
    • Can lead to compliance violations
    • Often driven by ease of access and user convenience
    Study this card →
  • Private Cloud

    Flip card

    A cloud computing environment dedicated exclusively to a single organization, offering enhanced control, security, and isolation.

    • Single-tenant architecture
    • High level of control and customization
    • Can be on-premises or hosted externally
    Study this card →
  • Least Privilege

    Flip card

    A security principle requiring that a user or system be given only the minimum levels of access or permissions needed to perform its job function.

    • Reduces the attack surface
    • Limits damage from compromised accounts
    • Essential for strong access control
    Study this card →
  • AWS IAM Least Privilege

    Flip card

    The security principle of granting users, roles, or services only the minimum permissions necessary to perform their intended tasks in AWS. This minimizes the potential blast radius of a security incident.

    • Achieved through carefully crafted IAM policies.
    • Reduces risk by limiting unauthorized access.
    • Essential for secure cloud operations, especially with serverless functions.
    Study this card →
  • Cloud Security Posture Management (CSPM)

    Flip card

    A cloud security technology that continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation.

    • Identifies security gaps in cloud infrastructure.
    • Ensures compliance with regulatory standards.
    • Automates remediation of misconfigurations.
    Study this card →
  • Public Cloud

    Flip card

    A cloud deployment model where computing services are delivered over the internet by a third-party provider, offering shared infrastructure and global availability.

    • Owned and operated by a third-party cloud service provider.
    • Resources are shared among multiple organizations.
    • Offers high scalability, elasticity, and global reach.
    Study this card →
  • Network Access Control List (NACL)

    Flip card

    A stateless packet filtering firewall that controls traffic in and out of one or more subnets within a Virtual Private Cloud (VPC). It operates at the subnet level.

    • Stateless: must explicitly allow both inbound and outbound traffic.
    • Operates at the subnet level.
    • Rules are evaluated in order, from lowest to highest.
    Study this card →
  • Data at Rest Encryption

    Flip card

    The cryptographic protection of data that is stored on any persistent storage media, ensuring its confidentiality even if the storage medium or underlying infrastructure is compromised.

    • Applies to data on hard drives, SSDs, object storage, databases.
    • Renders data unreadable without the decryption key.
    • Crucial for compliance and data breach prevention.
    Study this card →
  • Infrastructure as a Service (IaaS)

    Flip card

    A cloud computing service model where consumers are provided with virtualized computing resources (VMs, storage, networks) over the internet. The customer manages the operating systems and applications.

    • Provides fundamental computing resources.
    • Customer has control over OS, applications, and data.
    • Cloud provider manages virtualization, servers, storage, and networking hardware.
    Study this card →
  • Secure Hybrid Cloud Connectivity

    Flip card

    The practice of establishing secure and reliable network connections between on-premises infrastructure and cloud environments, typically using VPNs or dedicated links.

    • Ensures data privacy and integrity during transit
    • Extends on-premises security controls to the cloud
    • Facilitates consistent policy enforcement
    Study this card →
  • S3 Public Access Best Practice

    Flip card

    A fundamental security best practice for Amazon S3 (and similar object storage services) is to block all public access to buckets, especially those containing sensitive data, unless explicitly required and carefully controlled.

    • Default S3 buckets are private
    • Public access can be granted via bucket policies or ACLs
    • Tools like S3 Block Public Access can enforce this organization-wide
    Study this card →
  • Cloud Access Security Broker (CASB)

    Flip card

    A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud resources are accessed.

    • Addresses shadow IT, data security, threat protection, and compliance
    • Can enforce policies on sanctioned and unsanctioned cloud apps
    • Operates as a proxy, API integration, or log-based
    Study this card →
  • Secure Software Development Lifecycle (SSDLC)

    Flip card

    Integrating security practices and considerations into every phase of the software development lifecycle, from requirements gathering to deployment and maintenance.

    • Includes threat modeling, secure coding, security testing.
    • Aims to minimize vulnerabilities from the start.
    • Prevents common security flaws like hardcoded credentials.
    Study this card →
  • Data in Transit Encryption

    Flip card

    The process of encrypting data as it moves across networks, such as between a client application and a cloud service, to protect its confidentiality and integrity from eavesdropping or tampering.

    • Typically achieved using HTTPS/TLS.
    • Protects data during communication.
    • Complements data at rest encryption for comprehensive security.
    Study this card →
  • Federated Identity Management

    Flip card

    A system that allows users to use a single set of login credentials to access multiple applications and services across different security domains, often involving an on-premises identity provider and cloud services through a trusted relationship.

    • Enables Single Sign-On (SSO).
    • Relies on trusted relationships between identity providers.
    • Commonly uses protocols like SAML or OIDC.
    Study this card →
  • Platform as a Service (PaaS)

    Flip card

    A cloud service model that provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure.

    • Focus on application development and deployment
    • Provider manages OS, runtime, middleware
    • Scalable and flexible development environment
    Study this card →
  • Cloud Resilience

    Flip card

    The ability of a cloud system to withstand failures, adapt to changing conditions, and recover quickly from disruptions while maintaining acceptable levels of service.

    • Achieved through redundancy, fault tolerance, and disaster recovery
    • Often involves multi-region deployments
    • Ensures business continuity
    Study this card →
  • Serverless Least Privilege

    Flip card

    Applying the principle of least privilege to serverless functions by granting only the essential permissions required for each function to perform its specific task.

    • Minimizes potential damage from compromised functions
    • Reduces the attack surface
    • Requires careful design of IAM policies
    Study this card →
  • Data Encryption at Rest

    Flip card

    The process of encoding data while it is stored on a persistent storage medium, protecting it from unauthorized access even if the storage infrastructure is compromised.

    • Protects data confidentiality on disk or in storage.
    • Uses cryptographic algorithms to scramble data.
    • Requires a key for decryption and access.
    Study this card →
  • Cloud Dedicated Connection

    Flip card

    A dedicated, private network connection established between an organization's on-premises infrastructure and a cloud provider's network, bypassing the public internet.

    • Examples: AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect.
    • Offers higher bandwidth, lower latency, and enhanced security compared to VPN over internet.
    • Used for hybrid cloud architectures and large data transfers.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.