3.1 - CompTIA Security+

0.0(0)
studied byStudied by 1 person
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/33

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

34 Terms

1
New cards

Responsibility matrix

A diagram that defines the security responsibilities of both the cloud service provider and the customer.

2
New cards

Software as a Service (SaaS)

A cloud service model where the provider hosts applications for customers, allowing access via the internet.

3
New cards

Platform as a Service (PaaS)

A cloud service model that provides a platform for customers to develop and manage applications without worrying about infrastructure.

4
New cards

Infrastructure as a Service (IaaS)

A cloud service model offering virtualized computing resources over the internet (hardware, firmware, etc).

5
New cards

Hybrid cloud

A cloud deployment model that combines both public and private cloud infrastructures.

6
New cards

Hybrid cloud considerations

Managing public/private cloud security policies, integrating cloud environments with existing on-premise infrastructure.

7
New cards

Third-party vendors

External entities providing cloud services to businesses using various cloud models. As a third party, careful consideration regarding cloud service provider selection, contract negotiation, service performance, compliance, and communication practices is paramount.

8
New cards

Infrastructure as Code (IaC)

A software engineering practice that manages infrastructure through machine-readable definition files (e.g., XML, JSON).

9
New cards

Serverless architecture

A cloud deployment where the provider manages infrastructure and scales resources dynamically.

10
New cards

Microservices

Independent components running each application process as a service, communicating via lightweight APIs.

11
New cards

Air-gapped

A type of network isolation that physically separates a host from other networks.

12
New cards

Logical segmentation

Network topology management to restrict communication between network segments.

13
New cards

Software-defined networking (SDN)

Centralized control over a network’s structure, allowing dynamic configuration and improved management.

14
New cards

Management plane

Highest layer in SDN - monitors traffic conditions and network status.

15
New cards

Control plane

Makes decisions about how data should be forwarded/secured.

16
New cards

Data plane

Handles traffic switching/routing, and implementation of security controls.

17
New cards

On-premises network

A private network facility that an organization owns for employee use.

18
New cards

Centralized computing architecture

A model where all data processing/storage is performed in a single, central location.

19
New cards

Decentralized computing architecture

A model where data processing and storage are distributed across multiple locations.

20
New cards

Containerization

Virtualization technology for packaging applications into containers for easier deployment.

21
New cards

Application virtualization

A software delivery model streaming code from a server to clients.

22
New cards

Desktop virtualization

Technology enabling a desktop OS to run in a virtual environment on a server.

23
New cards

Internet of Things (IoT)

A network of interconnected devices communicating and exchanging data over the internet.

24
New cards

Industrial control systems (ICS)

Networks managing embedded devices and controlling automation processes.

25
New cards

Supervisory control and data acquisition (SCADA)

A type of ICS managing large-scale devices across wide geographical areas.

26
New cards

Embedded systems

Electronic systems designed for specific, dedicated functions.

27
New cards

High availability

An approach ensuring systems remain operational for maximum uptime.

28
New cards

Resilience (CSPs)

Cloud capabilities ensuring data remains available even during failures.

29
New cards

Scalability

The ability to dynamically expand or contract capacity based on demand.

30
New cards

Ease of deployment

Features allowing easy implementation of cloud infrastructure.

31
New cards

Risk transference

Shifting the financial burden of security risk to another party.

32
New cards

Ease of recovery

Features allowing organizations to regularly backup and restore data.

33
New cards

Patch availability

The accessibility of patches for cloud environments including automated management.

34
New cards

Inability to patch

Challenges organizations face in applying updates due to various factors.