CCSP Certification Exam Outline – Vocabulary Flashcards

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/33

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

34 Terms

1
New cards

CCSP (Certified Cloud Security Professional)

An ISC2 credential validating advanced knowledge and skills in cloud security architecture, design, operations and compliance.

2
New cards

ISC2

International Information System Security Certification Consortium, the organization that develops and administers the CCSP and other security certifications.

3
New cards

Domain 1 – Cloud Concepts, Architecture and Design

Exam section (17 % weight) covering core cloud definitions, roles, characteristics, reference architecture and secure design principles.

4
New cards

Domain 2 – Cloud Data Security

Exam section (20 % weight) addressing data life-cycle, storage architecture, classification, encryption, IRM, retention and auditability.

5
New cards

Domain 3 – Cloud Platform and Infrastructure Security

Exam section (17 % weight) focusing on secure data-center design, infrastructure components, risk analysis and BC/DR planning.

6
New cards

Domain 4 – Cloud Application Security

Exam section (17 % weight) dealing with secure SDLC, cloud-specific vulnerabilities, software assurance, API security and IAM solutions.

7
New cards

Domain 5 – Cloud Security Operations

Exam section (16 % weight) covering build, operate and maintain tasks, operational controls, logging, incident response and SOC activities.

8
New cards

Domain 6 – Legal, Risk and Compliance

Exam section (13 % weight) examining legal requirements, privacy, audits, enterprise risk and outsourcing/contract issues in cloud.

9
New cards

On-demand self-service

Cloud characteristic allowing customers to unilaterally provision computing capabilities automatically without human interaction with the provider.

10
New cards

Broad network access

Cloud characteristic enabling capabilities to be available over the network and accessed through standard mechanisms by diverse client platforms.

11
New cards

Multi-tenancy

Cloud feature where resources are pooled to serve multiple customers using separation mechanisms so each tenant is isolated.

12
New cards

Rapid elasticity and scalability

Capability to quickly expand or shrink resources, giving the impression of unlimited capacity to the customer.

13
New cards

Resource pooling

Provider’s use of multi-tenant model to dynamically assign and reassign physical or virtual resources according to consumer demand.

14
New cards

Measured service

Cloud systems automatically control and optimize resource use by leveraging a metering capability, providing transparency for both provider and consumer.

15
New cards

Virtualization

Technology that abstracts computing resources—such as servers, storage or networks—forming the foundation of most cloud services.

16
New cards

Software as a Service (SaaS)

Cloud service category where consumers use provider-hosted applications running on a cloud infrastructure via thin client interfaces.

17
New cards

Platform as a Service (PaaS)

Cloud service category supplying a platform—runtime, middleware and tools—for customers to deploy or develop applications.

18
New cards

Infrastructure as a Service (IaaS)

Cloud service category offering fundamental computing resources—processing, storage, networking—allowing the consumer to deploy arbitrary software.

19
New cards

Public cloud

Deployment model where cloud infrastructure is provisioned for open use by the general public and owned by an organization selling cloud services.

20
New cards

Private cloud

Cloud infrastructure operated solely for a single organization, managed internally or by a third party, and may exist on or off premises.

21
New cards

Hybrid cloud

Composition of two or more distinct cloud infrastructures (private, public, community) bound by standardized technology enabling data and application portability.

22
New cards

Community cloud

Cloud infrastructure shared by several organizations supporting a specific community with shared concerns (e.g., mission, policy, security requirements).

23
New cards

Multi-cloud

Use of two or more cloud services from different providers to avoid vendor lock-in or improve resilience.

24
New cards

Cloud service customer

Entity that acquires or uses cloud services from a provider.

25
New cards

Cloud service provider

Party responsible for making a service available to interested customers.

26
New cards

Cloud service broker

Entity that manages use, performance and delivery of cloud services and negotiates relationships between providers and consumers.

27
New cards

Cloud service partner

Organization offering supplementary services such as integration, customization or consulting for cloud solutions.

28
New cards

Regulator (cloud context)

Government or industry body that enforces compliance requirements applicable to cloud environments.

29
New cards

Reference architecture

Standardized architecture diagram or description providing a template solution for cloud deployment and integration patterns.

30
New cards

Secure data life-cycle

Framework outlining protection requirements for data through create, store, use, share, archive and destroy phases in cloud.

31
New cards

Business Continuity (BC)

Capability of an organization to continue delivery of products or services at acceptable predefined levels following a disruptive incident.

32
New cards

Disaster Recovery (DR)

Strategies and plans for restoring IT systems and operations after a catastrophic event in the cloud or data center.

33
New cards

Business Impact Analysis (BIA)

Process that identifies critical business functions, quantifies impact of disruptions and helps set recovery priorities and investments.

34
New cards

DevOps security

Integration of s