1/70
Vocabulary flashcards covering core concepts from D320 Managing Cloud Security, including cloud storage risks, SDLC phases, encryption, incident response, privacy regulations, and deployment models.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Share Phase
The phase of the cloud data life cycle that requires adherence to export and import restrictions, including Export Administration Regulations (EAR) and the Wassenaar Arrangement.
Data Striping
A storage method used in most RAID configurations that allows efficient data recovery because if one drive fails, other drives fill in the missing data.
Egress Monitoring Tools
Tools used to prevent data from going outside the control of an organization.
Ephemeral Storage
A type of cloud storage that carries the highest risk of losing forensic artifacts in the event of an incident response investigation.
Privacy Notice
A document used to determine if a company has properly disclosed information about what personal and environmental data it collects from an application's users.
Hashing
A technique used to securely store passwords in a database so that the data is not available to system administrators.
Anonymization
A data masking technique used to prevent attackers from identifying individuals in sensitive and classified cloud data in the event of a data breach.
Labeling
A technique used to quickly identify the document owner in a shared network folder.
Structured Data
A data type used when introducing a new data standard to ensure system inventory data is efficiently discovered and processed.
Replication Restrictions
An IRM challenge encountered when attempting to protect critical data from storage failures using cloud backup alongside IRM controls.
Crypto-shredding
A data destruction method for solid-state drives (SSDs) that ensures data cannot be retrieved by sanitizing encryption keys.
SIEM (Security Information and Event Management)
A system used to gather and interpret logs from an organization's cloud environment.
Automated Analysis of Data Sets
A SIEM policy used to minimize errors or missed security issues caused by human log analysis.
Hypervisor
Software that allows multiple operating systems to run on the same physical server in a virtualized environment.
Orchestration
The process of automatically provisioning, configuring, and managing virtual machines and other resources in a virtualized environment.
Metered Service
A cloud computing characteristic that allows customers to manage their utilization by paying only for the resources used.
Multi-cloud
A cloud deployment model allowing customers to leverage service and price differences across two or more cloud vendors.
Resiliency
A cloud consideration referring to the ability of the infrastructure to withstand disruptive events.
Transport Layer Security (TLS)
A technology used to protect the confidentiality of data from on-path attacks.
Key Escrow
A technology that allows cryptographic secrets to be held in a secure way so that authorized parties can recover them.
Network Security Group
A safety control that acts as a virtual firewall in cloud environments.
Geofencing
An architectural concept implemented to restrict access so that only users at specific physical locations can administer cloud resources.
Toolkit
A BC/DR term referring to a secure container holding all necessary documentation and resources needed to conduct a proper BC/DR response action.
Vendor Lock-in
The cloud risk of a customer being unable to easily move data or switch providers, such as when data is stored in a proprietary format.
Interoperability
An architectural concept addressing the seamless syncing and compatibility between different cloud service provider offerings.
Reliability
A design pillar representing the ability of a workload to execute its intended function accurately and consistently when expected.
Secrets Management
A cloud provider service used to securely store and administer API tokens or cryptographic keys across systems.
FedRAMP
A program used to assess vendor compliance with United States governmental regulations for data management.
Virtualization Toolsets
Software used to provide enhanced functionality, such as improved networking or video output, for a guest operating system connecting to the host hardware.
Hardware Abstraction
A concept and advantage of virtualized environments that enables high availability by decoupling software from physical hardware.
Loosely Coupled Clusters
A storage architecture containing nodes that are logically connected rather than physically connected.
Intrusion Prevention System (IPS)
A system that actively detects and stops malicious traffic, unlike an IDS which detects and alerts.
Control Plane
The part of a network that a SIEM suite uses to verify that network devices in a software-defined network are properly forwarding traffic.
Vulnerability Scanner
A type of scanner used to inspect hosts for misconfigurations and known security threats.
Availability Management
An ITSM process implemented to ensure and improve the resiliency and uptime of critical IT services for users.
Recovery Time Objective (RTO)
A metric used to measure the target time allowed to return systems to operational capability following an outage.
Release Management
A management process focused on arranging elements needed to deploy software—including QA testing and staging—before active maintenance.
Electronic Discovery (e-discovery)
The process used to identify, collect, and produce stored electronic database records for legal proceedings.
Secondary Communication Channel
An alternate communication path established between supply chain parties for use during a disaster situation.
Broken Access Control
An OWASP Top 10 vulnerability category involving flaws such as insecure direct object identifiers that allow unauthorized account viewing.
Cryptographic Failures
An OWASP Top 10 vulnerability category related to the use of weak algorithms or protocols for protecting data.
Black Box Testing
A zero-knowledge testing technique performed by security consultants to simulate external hacker attacks.
Quality Assurance (QA)
The process involving multiple teams and roles testing code end-to-end to ensure standards and requirements are met.
Rate Limiting
An API security feature implemented to control traffic volume and prevent API overuse.
Manual Updates
An operational control ensuring that untested vendor updates are not run automatically in mission-critical environments.
Waterfall
A sequential software development methodology where each phase follows the previous phase without overlap.
Requirements Definition
An SDLC phase involving gathering customer input and prioritizing features based on system functionality needs.
Reverse Proxy
A WAF feature that shields application servers by intercepting and forwarding client requests.
Full-disk Encryption
An encryption scheme providing security against data theft if an entire physical solid-state drive is stolen.
Tier 4 Data Center
A data center tier configured with independent, physically isolated systems, multiple distribution paths, and fault tolerance.
Distributed Resource Scheduling
A management concept focused on balancing virtual machines across clusters to optimize performance.
Remote Desktop Protocol (RDP)
A native Windows protocol used to provide encrypted remote management access to systems.
Controlled Entry Point
A physical access security control requiring visitor sign-ins and temporary badges at reception areas.
Zero Trust
A security model that requires explicit identity and access validation for every user before granting data access.
Dry Run Testing
A low-impact disaster recovery test focused on checking contact lists and call trees with minimal operational activity.
CLOUD Act
A US law mandating US companies to provide data to federal officials regardless of physical storage location or local legal conflicts.
Chain of Custody
The chronological documentation showing the handling, custody, transfer, and analysis of evidence for legal presentation.
Gap Analysis
A comparison analysis evaluated against a baseline standard to identify operational or security deficiencies.
Scope Limitation
An auditor opinion statement indicating that sufficient information was not disclosed to complete a fair audit.
Risk Avoidance
A risk response strategy involving altering business practices to eliminate an identified risk entirely.
Risk Acceptance
A risk management strategy of maintaining standard operations after acknowledging an existing risk.
Service Level Agreement (SLA)
A contract specifying agreed-upon vendor performance metrics and remedies for failures.
Master Service Agreement (MSA)
A foundational contract governing long-term vendor engagements, typically incorporating standard security requirements.
Business Requirements
The operational goals and requirements of an organization that drive its security decisions.
Type 1 Hypervisor
A bare-metal hypervisor type standardly deployed in cloud provider data centers.
Business Impact Analysis (BIA)
An assessment used to determine an organization's critical business processes, paths, and core assets.
Private Cloud
A cloud model owned and operated exclusively for a single organization's internal use.
Public Cloud
A cloud deployment model owned by a provider that offers multi-tenant services to external subscribers.
Community Cloud
A shared cloud infrastructure shared among organizations with common concerns or affinity groups.
VM Escape
A security threat where an attacker breaks out of a guest virtual machine to compromise the hypervisor.
Software as a Service (SaaS)
A cloud service model where the cloud vendor runs hosted applications on its own infrastructure for customer use.