D320 - Managing Cloud Security Vocabulary

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/70

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering core concepts from D320 Managing Cloud Security, including cloud storage risks, SDLC phases, encryption, incident response, privacy regulations, and deployment models.

Last updated 11:50 PM on 8/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

71 Terms

1
New cards

Share Phase

The phase of the cloud data life cycle that requires adherence to export and import restrictions, including Export Administration Regulations (EAR) and the Wassenaar Arrangement.

2
New cards

Data Striping

A storage method used in most RAID configurations that allows efficient data recovery because if one drive fails, other drives fill in the missing data.

3
New cards

Egress Monitoring Tools

Tools used to prevent data from going outside the control of an organization.

4
New cards

Ephemeral Storage

A type of cloud storage that carries the highest risk of losing forensic artifacts in the event of an incident response investigation.

5
New cards

Privacy Notice

A document used to determine if a company has properly disclosed information about what personal and environmental data it collects from an application's users.

6
New cards

Hashing

A technique used to securely store passwords in a database so that the data is not available to system administrators.

7
New cards

Anonymization

A data masking technique used to prevent attackers from identifying individuals in sensitive and classified cloud data in the event of a data breach.

8
New cards

Labeling

A technique used to quickly identify the document owner in a shared network folder.

9
New cards

Structured Data

A data type used when introducing a new data standard to ensure system inventory data is efficiently discovered and processed.

10
New cards

Replication Restrictions

An IRM challenge encountered when attempting to protect critical data from storage failures using cloud backup alongside IRM controls.

11
New cards

Crypto-shredding

A data destruction method for solid-state drives (SSDs) that ensures data cannot be retrieved by sanitizing encryption keys.

12
New cards

SIEM (Security Information and Event Management)

A system used to gather and interpret logs from an organization's cloud environment.

13
New cards

Automated Analysis of Data Sets

A SIEM policy used to minimize errors or missed security issues caused by human log analysis.

14
New cards

Hypervisor

Software that allows multiple operating systems to run on the same physical server in a virtualized environment.

15
New cards

Orchestration

The process of automatically provisioning, configuring, and managing virtual machines and other resources in a virtualized environment.

16
New cards

Metered Service

A cloud computing characteristic that allows customers to manage their utilization by paying only for the resources used.

17
New cards

Multi-cloud

A cloud deployment model allowing customers to leverage service and price differences across two or more cloud vendors.

18
New cards

Resiliency

A cloud consideration referring to the ability of the infrastructure to withstand disruptive events.

19
New cards

Transport Layer Security (TLS)

A technology used to protect the confidentiality of data from on-path attacks.

20
New cards

Key Escrow

A technology that allows cryptographic secrets to be held in a secure way so that authorized parties can recover them.

21
New cards

Network Security Group

A safety control that acts as a virtual firewall in cloud environments.

22
New cards

Geofencing

An architectural concept implemented to restrict access so that only users at specific physical locations can administer cloud resources.

23
New cards

Toolkit

A BC/DR term referring to a secure container holding all necessary documentation and resources needed to conduct a proper BC/DR response action.

24
New cards

Vendor Lock-in

The cloud risk of a customer being unable to easily move data or switch providers, such as when data is stored in a proprietary format.

25
New cards

Interoperability

An architectural concept addressing the seamless syncing and compatibility between different cloud service provider offerings.

26
New cards

Reliability

A design pillar representing the ability of a workload to execute its intended function accurately and consistently when expected.

27
New cards

Secrets Management

A cloud provider service used to securely store and administer API tokens or cryptographic keys across systems.

28
New cards

FedRAMP

A program used to assess vendor compliance with United States governmental regulations for data management.

29
New cards

Virtualization Toolsets

Software used to provide enhanced functionality, such as improved networking or video output, for a guest operating system connecting to the host hardware.

30
New cards

Hardware Abstraction

A concept and advantage of virtualized environments that enables high availability by decoupling software from physical hardware.

31
New cards

Loosely Coupled Clusters

A storage architecture containing nodes that are logically connected rather than physically connected.

32
New cards

Intrusion Prevention System (IPS)

A system that actively detects and stops malicious traffic, unlike an IDS which detects and alerts.

33
New cards

Control Plane

The part of a network that a SIEM suite uses to verify that network devices in a software-defined network are properly forwarding traffic.

34
New cards

Vulnerability Scanner

A type of scanner used to inspect hosts for misconfigurations and known security threats.

35
New cards

Availability Management

An ITSM process implemented to ensure and improve the resiliency and uptime of critical IT services for users.

36
New cards

Recovery Time Objective (RTO)

A metric used to measure the target time allowed to return systems to operational capability following an outage.

37
New cards

Release Management

A management process focused on arranging elements needed to deploy software—including QA testing and staging—before active maintenance.

38
New cards

Electronic Discovery (e-discovery)

The process used to identify, collect, and produce stored electronic database records for legal proceedings.

39
New cards

Secondary Communication Channel

An alternate communication path established between supply chain parties for use during a disaster situation.

40
New cards

Broken Access Control

An OWASP Top 10 vulnerability category involving flaws such as insecure direct object identifiers that allow unauthorized account viewing.

41
New cards

Cryptographic Failures

An OWASP Top 10 vulnerability category related to the use of weak algorithms or protocols for protecting data.

42
New cards

Black Box Testing

A zero-knowledge testing technique performed by security consultants to simulate external hacker attacks.

43
New cards

Quality Assurance (QA)

The process involving multiple teams and roles testing code end-to-end to ensure standards and requirements are met.

44
New cards

Rate Limiting

An API security feature implemented to control traffic volume and prevent API overuse.

45
New cards

Manual Updates

An operational control ensuring that untested vendor updates are not run automatically in mission-critical environments.

46
New cards

Waterfall

A sequential software development methodology where each phase follows the previous phase without overlap.

47
New cards

Requirements Definition

An SDLC phase involving gathering customer input and prioritizing features based on system functionality needs.

48
New cards

Reverse Proxy

A WAF feature that shields application servers by intercepting and forwarding client requests.

49
New cards

Full-disk Encryption

An encryption scheme providing security against data theft if an entire physical solid-state drive is stolen.

50
New cards

Tier 4 Data Center

A data center tier configured with independent, physically isolated systems, multiple distribution paths, and fault tolerance.

51
New cards

Distributed Resource Scheduling

A management concept focused on balancing virtual machines across clusters to optimize performance.

52
New cards

Remote Desktop Protocol (RDP)

A native Windows protocol used to provide encrypted remote management access to systems.

53
New cards

Controlled Entry Point

A physical access security control requiring visitor sign-ins and temporary badges at reception areas.

54
New cards

Zero Trust

A security model that requires explicit identity and access validation for every user before granting data access.

55
New cards

Dry Run Testing

A low-impact disaster recovery test focused on checking contact lists and call trees with minimal operational activity.

56
New cards

CLOUD Act

A US law mandating US companies to provide data to federal officials regardless of physical storage location or local legal conflicts.

57
New cards

Chain of Custody

The chronological documentation showing the handling, custody, transfer, and analysis of evidence for legal presentation.

58
New cards

Gap Analysis

A comparison analysis evaluated against a baseline standard to identify operational or security deficiencies.

59
New cards

Scope Limitation

An auditor opinion statement indicating that sufficient information was not disclosed to complete a fair audit.

60
New cards

Risk Avoidance

A risk response strategy involving altering business practices to eliminate an identified risk entirely.

61
New cards

Risk Acceptance

A risk management strategy of maintaining standard operations after acknowledging an existing risk.

62
New cards

Service Level Agreement (SLA)

A contract specifying agreed-upon vendor performance metrics and remedies for failures.

63
New cards

Master Service Agreement (MSA)

A foundational contract governing long-term vendor engagements, typically incorporating standard security requirements.

64
New cards

Business Requirements

The operational goals and requirements of an organization that drive its security decisions.

65
New cards

Type 1 Hypervisor

A bare-metal hypervisor type standardly deployed in cloud provider data centers.

66
New cards

Business Impact Analysis (BIA)

An assessment used to determine an organization's critical business processes, paths, and core assets.

67
New cards

Private Cloud

A cloud model owned and operated exclusively for a single organization's internal use.

68
New cards

Public Cloud

A cloud deployment model owned by a provider that offers multi-tenant services to external subscribers.

69
New cards

Community Cloud

A shared cloud infrastructure shared among organizations with common concerns or affinity groups.

70
New cards

VM Escape

A security threat where an attacker breaks out of a guest virtual machine to compromise the hypervisor.

71
New cards

Software as a Service (SaaS)

A cloud service model where the cloud vendor runs hosted applications on its own infrastructure for customer use.