1/38
Comprehensive vocabulary flashcards covering Domain 1 of the CCSP curriculum, including cloud definitions, roles, characteristics, models, security concepts, and regulatory frameworks.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cloud Computing (NIST Definition)
A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
Cloud Service Customer (CSC)
The entity that consumes cloud services.
Cloud Service Provider (CSP)
The entity that provides cloud services.
Cloud Service Partner
An entity that provides support or auxiliary services to a CSP, a CSC, or both.
On-Demand Self-Service
A cloud characteristic where a consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.
Broad Network Access
A cloud characteristic where capabilities are available over the network and accessed through standard mechanisms that promote use by thin or thick client platforms.
Resource Pooling
The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand.
Rapid Elasticity
Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand.
Measured Service
Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts).
Cloud Orchestration
The operational process for receiving, fulfilling, managing, monitoring, and metering customer services across all portions of the cloud infrastructure.
Capital Expenditure (CapEx)
Traditional IT cost model involving high up-front investments in physical infrastructure.
Operational Expenditure (OpEx)
The cost model used in cloud computing where expenses are ongoing and variable based on usage.
ISO/IEC 17789 Viewpoints
The four distinct viewpoints of the Cloud Computing Reference Architecture (CCRA): User view, Functional view, Implementation view, and Deployment view.
Communications as a Service (CaaS)
A cloud service category within the ISO/IEC cloud capability types.
Platform as a Service (PaaS)
A cloud service model where the provider provides a platform (including multiple languages, frameworks, and environments) for the consumer to deploy created or acquired applications.
Infrastructure as a Service (IaaS)
A cloud service model providing scale, converged networks, and on-demand self-service capacity for infrastructure resources.
Software as a Service (SaaS)
A cloud service model where the consumer uses the provider’s applications running on a cloud infrastructure.
Private Cloud
Cloud infrastructure owned or leased by a single organization and operated solely for that organization.
Public Cloud
Cloud infrastructure owned by an organization selling cloud services to the general public or a large industry group.
Community Cloud
Cloud infrastructure shared by several organizations and supporting a specific community with shared concerns such as mission, security requirements, and policy.
Hybrid Cloud
A cloud infrastructure composed of two or more distinct cloud infrastructures (private, community, or public) bound together by technology that enables data and application portability.
Multicloud
The use of services from multiple CSPs instead of a single CSP.
CIA Triad
The foundation of security concepts: Confidentiality, Integrity, and Availability.
Cryptography
The practice of disguising information to provide confidentiality, integrity, authenticity, and non-repudiation.
Encryption Key Management
The process of overseeing cryptographic keys through their lifecycle: creation, issuance, revocation, recovery, distribution, and destruction.
Physical Destruction
A media sanitization option involving the physical rendering of hardware as unusable.
Degaussing
A media sanitization option using powerful magnets to disrupt recorded magnetic domains on storage media.
Cryptographic Erasure
A media sanitization option where the encryption keys for data are destroyed, making the stored data unrecoverable.
Zero Trust Network
A security model where no user or system is trusted by default, often involving continuous authentication and inspection of traffic.
Ephemeral Computing
Also known as nonpersistent computing; an approach using virtual systems or containerized applications.
Role-Based Access Control (RBAC)
An access control system where users are mapped to specific roles, and those roles are granted access to applications or resources.
Cloud Secure Data Life Cycle
The six common phases of data: Creation, Storage, Usage, Sharing, Archiving, and Destruction.
Data Replication
The practice of maintaining an up-to-date copy of required data in a different location to address the loss of important assets.
Business Impact Analysis (BIA)
The process of predicting or calculating the consequences of disruption to a business function to set protection needs for CIA.
Cloud Controls Matrix (CCM)
A compilation of cloud-relevant security controls developed by the Cloud Security Alliance (CSA) that can be related to other control frameworks.
STAR Registry
The Security, Trust Assurance and Risk Registry by the CSA, used for self-assessments and third-party assessments of CSPs.
Common Criteria
The ISO/IEC 15408 standard consisting of Protection Profiles (PP), Target of Evaluation (ToE), Security Target (ST), and Evaluation Assurance Levels (EALs).
Agentic AI
Autonomous AI systems that perform work and adapt in pursuit of a specific goal.
Cloud Bursting
A concept allowing public cloud resources to be utilized when a private cloud workload reaches its maximum capacity.