ccsp domain 1

0.0(0)
Studied by 6 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/110

flashcard set

Earn XP

Description and Tags

isc2 ccsp exam

Last updated 8:58 PM on 1/5/23
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

111 Terms

1
New cards
• Cloud app (cloud application)
Short for cloud application, cloud app is the phrase used to describe a software application that is never installed on a local computer. Instead, it is accessed via the internet.
2
New cards
• Cloud computing
A type of computing that relies on sharing computing resources in the delivery of computing services, rather than having local servers or personal devices to handle applications.
3
New cards
• Cloud computing role
A set of activities that serves a common purpose.
4
New cards
• Cloud database
A database accessible to clients from the cloud and delivered to users on demand via the internet. Cloud databases can use cloud computing to achieve optimized scaling, high availability, multitenancy and effective resource allocation.
5
New cards
• Cloud management
Software and technologies designed for operating and monitoring the applications, data and services residing in the cloud. Cloud management tools help ensure a company's cloud computing-based resources are working optimally and properly interacting with users and other services.
6
New cards
• Cloud migration
The process of transitioning all or part of a company's data, applications and services from on-site premises behind the firewall to the cloud, where the information can be provided over the internet on an on-demand basis.
7
New cards
• Cloud operating system (OS)
A software application responsible for orchestrating cloud computing services across multiple geographically separated data centers.
8
New cards
• Cloud service customer (CSC)
A party that is in a business relationship for the purpose of using cloud services.
9
New cards
Cloud auditor
responsible for conducting audits of cloud systems and cloud apps
10
New cards
cloud service broker
partner that serves as an intermediary between a cloud service customer and cloud service provider.
11
New cards
• Cloud service provider (CSP)
A service provider who offers customers storage or software solutions available via a public network, usually the internet.
12
New cards
• Cloud storage
The storage of data online in the cloud, wherein a company's data is stored in and accessible from multiple distributed and connected resources that make up a cloud.
13
New cards
• Cloud workload
An application, service or capability running within the cloud environment.
14
New cards
• Confidential computing
Confidential computing protects data in use by performing computation in a hardware-based Trusted Execution Environment. Source: Confidential Computing Consortium, https://confidentialcomputing.io/
15
New cards
• Hybrid cloud
A combination of public and private cloud storage where some critical data resides in the enterprise's private cloud while other data is stored and accessible from a public cloud storage provider.
16
New cards
Public Cloud
cloud is maintained and controlled by the cloud provider, but the services are available to any potential cloud customers.
17
New cards
• Infrastructure as a Service (IaaS)
Computer infrastructure, typically computer, storage and networking services, being delivered as a service. IaaS is popular in the data center where software and servers are purchased as a fully outsourced service and usually billed on usage and how much of the resource is used.
18
New cards
• Multitenancy
Describes multiple customers using the same public cloud.
19
New cards
• Peer cloud service provider
A cloud service provider who provides one or more cloud services for use by one or more other cloud service providers as part of their cloud services.
20
New cards
• Platform as a Service (PaaS)
A cloud service through which the cloud service customer can deploy, manage and run customer-created or customer-acquired applications using one or more programming languages and one or more executing environments supported by the cloud service provider.
21
New cards
• Portability
When applied to cloud services, it defines the ease with which applications or components are moved and reused elsewhere regardless of the provider, platform, OS, infrastructure, location, storage, format of data or APIs.
22
New cards
• Private cloud
The phrase used to describe a cloud computing platform that is implemented within the corporate firewall, under the control of the IT department. A private cloud is designed to offer the same features and benefits of cloud systems but removes a number of objections to the cloud computing model, including control over enterprise and customer data, worries about security and issues connected to regulatory compliance.
23
New cards
• Product catalog
A listing of all the cloud service products that cloud service providers make available to cloud service customers.
24
New cards
• Provisioning
When applied to cloud services, the processes associated with delivering and orchestrating cloud computing services. It also includes facilities for interfacing with the cloud's applications and services as well as auditing and monitoring who accesses and utilizes the resources.
25
New cards
• Software as a Service (SaaS)
A software delivery method that provides access to software and its functions remotely as a web-based service. SaaS allows organizations to access business functionality at a cost typically less than paying for licensed applications since SaaS pricing is based on a monthly fee.
26
New cards
• Sub-role
A subset of the activities of a given role.
27
New cards
• Virtual machine
A system that allows multiple virtual systems to share a common physical implementation.
28
New cards
Cloud application portability
migrate a cloud app from one cloud provider to another
29
New cards
cloud data portability
ability to move data between cloud providers
30
New cards
cloud deployment model
how cloud computing is delivered through a set of configurations: public, private, hybrid, community
31
New cards
Cloud Service
capabilities offered via a cloud provider and accessible via a client.
32
New cards
Cloud service category
group of cloud services that have a common set of features or qualities.
33
New cards
community cloud
cloud services model where the tenants are limited to those that have a relationship together with shared requirements, and are maintained or controlled by at least onemember of the community.
34
New cards
tenant
one or more cloud customers sharing access to a pool of resources.
35
New cards
data portability
ability to move data from one system or another without having to re-enter it.
36
New cards
Measured Service
cloud services are delivered and billed for in a metered way
37
New cards
on-demand self-service
cloud customer can provision services in an automatic manner, when needed, with minimal involvement from the cloud provider
38
New cards
resource pooling
aggregation of resources allocated to cloud customers by the cloud provider.
39
New cards
reversibility
ability of a cloud customer to remove all data and applications from a cloud provider and completely remove all data from their environment and move to new environment with minimal impact to operations.
40
New cards
cloud computing roles
auditor, service broker, service customer, service partner, service provider, service user
41
New cards
cloud computing characteristics
on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service
42
New cards
What are the fundamental keys to cloud implementation? (4)
CPU
memory/RAM
networking
storage solutions
43
New cards
Cloud computing activities
activities are performed by the cloud service customer
44
New cards
Roles for the cloud service customer
service user
service administrator
service business manager
service integrator
45
New cards
cloud service integrator
connects and integrates existing systems and services to the cloud
46
New cards
roles for cloud service providers
service operations manager
service deployment manager
service manager
service business manager
support and care representative
inter-cloud provider
service security and risk manager
network provider
47
New cards
cloud service operations manager
prepares systems for the cloud, administers service, monitors services, provides audit data when requested or required, manages inventory and assets.
48
New cards
cloud service deployment manager
gathers metrics on cloud services, manages deployment steps and processes, defines the processes and environment.
49
New cards
cloud service manager
delivers, provisions, and manages the cloud services
50
New cards
inter-cloud provider
responsible for peering with other cloud services and providers as well as overseeing
51
New cards
cloud service capabilities
infrastructure service capability
platform service capability
software service capability
52
New cards
infrastructure service capability
cloud customer can provision and have substantial configuration control over processing, storage, and net resources.
53
New cards
platform service capability
cloud customer can deploy code and apps using programming languages and libraries that are maintained by the CSP.
54
New cards
software service capability
cloud cust uses a fully established app provided by the cloud provider, with minimal user configuration options allowed.
55
New cards
cloud service categories
Infrastructure as a Service (IaaS)
Platform as a service (PaaS)
Software as a service (SaaS)
56
New cards
Infrastructure as a Service (IaaS)
limited control over network components for the customer, customer can deploy and run arbitrary software and systems.
57
New cards
Platform as a Service (PaaS)
customer is responsible for deploying their apps within the provided platform infrastructure, cloud provider is responsible for patching and deploying systems
58
New cards
Software as a Service (SaaS)
provider is responsible for maintaining the entire system and all underlying infrastructure, customer has limited configuration options
59
New cards
what are the key benefits/features of IaaS?
scalability
cost of ownership of physical hardware
high availability
physical security req via CSProvider
location and access independence
metered usage-only pay for what you need
potential for "green" data centers
60
New cards
what are the key benefits/features of PaaS?
auto-scaling
multiple host environments
choice of environments
flexibility
ease of upgrades
cost effective
ease of access
licensing
61
New cards
auto-scaling vs. scaling
auto-scaling is found in PaaS and the provider changes the size automatically
scaling- the user does all changes
62
New cards
what are the key features/benefits of SaaS?
supports costs and efforts
reduced overall costs
licensing
ease of use and administration
standardization
63
New cards
what are the cloud deployment models?
public
private
hybrid
community
64
New cards
what are the key benefits/features of the public cloud model?
easy setup
scalability
only pay for what you need
65
New cards
What standards does ISC cloud follow?
NIST SP standards
66
New cards
key benefits/features of private cloud
the customer owns it
ops and system parameters are controlled by the controlling org
control over data and software
67
New cards
hybrid cloud benefits/features
split systems for optimization - user can split resources between public and private
retain critical systems internally
disaster recovery - can mitigate data back and forth from private to public
scalability
68
New cards
interoperability
ease with which one can move or reuse comps of an app or service.
69
New cards
SLA
service level agreements - terms and cost agreements of services
70
New cards
what is the main way a cloud provider implements security?
by setting baselines and minimum standards with add-ons and extensions.
71
New cards
analytical AI
cognitive-based, focuses on systems to analyze data from past experiences for future decisions.
72
New cards
human-inspired AI
picks up where analytical AI leaves off by incorporating emotional intelligence.
73
New cards
machine learning
uses scientific and statistical data and algorithms to allow machines to adapt to situations and perform functions they are programmed to perform.
74
New cards
examples of machine learning
intrusion detection

e-mail filtering

virus scanning
75
New cards
blockchain
list of records that linked together via cryptography
76
New cards
types of blockchains(4)
public

private

consortium - req. permission to join

hybrid - combo of all three
77
New cards
mobile device management (MDM)
suite of policies, tech and infrastructure that enables an org to manage and secure mobile access to data.
78
New cards
How is MDM accomplished?
by installing software from the IT dept to enforce security configurations and policies.
79
New cards
containers
rapid deployment of applications throughout cloud environments
80
New cards
Security Concepts relevant to cloud computing
cryptography

access control

data and media sanitation

network security

virtualization security

common threats
81
New cards
data in transit
state of data when it is actually being used by an application and is traversing systems internally
82
New cards
data at rest
information stored on a system or device
83
New cards
types of key management systems(KMSs)
remote

client-side
84
New cards
remote KMS
system maintained by the customer at their location.
85
New cards
client-side KMS
provided by the cloud provider but is hosted and controlled by the customer
86
New cards
accounting when working with authentication and authorisation
maintains logs and records of all activities for both operation and reg needs.
87
New cards
LDAP
lightweight directory access protocol
88
New cards
what does an LDAP do?
authenticator when a user logs into a system
89
New cards
authorization vs. authentication
authorization is an on-going even during the authenticated session
90
New cards
two issues in data and media sanitation

1. ability to easily and efficiently move data from one cloud provider to another
2. ability to ensure that all data has been removed and sanitized when leaving a cloud provider or environment.
91
New cards
data overwriting
write over erased data with either arbitrary data or zero values.
92
New cards
what is the practice for destroying keys?
cryptographic erasing
93
New cards
type 1 hypervisor
tied to the underlying hardware and hosts virtual machines on top of it. operates between hardware and host layer.
94
New cards
type 2 hypervisor
software based and resides on the host itself.
95
New cards
common threats
data breaches

insufficient ID, cred, access management

insecure interfaces and APIs

system vulnerabilities

account hijacking

malicious insiders

advanced persistent threats

data loss

insufficient due diligence

abuse and nefarious use of cloud services

denial of service

shared technologies issues
96
New cards
security concerns for IaaS
multitenancy

co-location

hypervisor security and attacks

network security

VM attacks

virtual switch attacks

DoS
97
New cards
co-location
when multiple VM’s hosted by the same physical hardware start attacking each other including hypervisor.
98
New cards
Why is a virtual machine attack riskier than a physical server?
because a VM is sharing a host with other VMs and the attack can spread across the network faster and easier.
99
New cards
virtual and physical switches are attacked at layer…
2
100
New cards
security concerns for PaaS
system isolation

user permissions

user access

malware, trojans, backdoors, etc.

Explore top notes

note
OZV casus 7
Updated 432d ago
0.0(0)
note
Chapter 10: Factor Markets
Updated 1066d ago
0.0(0)
note
AP Government Units 1 & 2
Updated 396d ago
0.0(0)
note
AP Microeconomics Formula Sheet
Updated 485d ago
0.0(0)
note
Diseases: Cause and Control
Updated 1085d ago
0.0(0)
note
4.3 Cycles of Matter >
Updated 419d ago
0.0(0)
note
AP Calculus BC Ultimate Guide
Updated 1072d ago
0.0(0)
note
OZV casus 7
Updated 432d ago
0.0(0)
note
Chapter 10: Factor Markets
Updated 1066d ago
0.0(0)
note
AP Government Units 1 & 2
Updated 396d ago
0.0(0)
note
AP Microeconomics Formula Sheet
Updated 485d ago
0.0(0)
note
Diseases: Cause and Control
Updated 1085d ago
0.0(0)
note
4.3 Cycles of Matter >
Updated 419d ago
0.0(0)
note
AP Calculus BC Ultimate Guide
Updated 1072d ago
0.0(0)

Explore top flashcards

flashcards
Lesson 1
20
Updated 729d ago
0.0(0)
flashcards
AP Gov Terms
114
Updated 96d ago
0.0(0)
flashcards
Cells-Important Vocab
49
Updated 469d ago
0.0(0)
flashcards
GLW #2
20
Updated 185d ago
0.0(0)
flashcards
Personality
54
Updated 1127d ago
0.0(0)
flashcards
Lesson 1
20
Updated 729d ago
0.0(0)
flashcards
AP Gov Terms
114
Updated 96d ago
0.0(0)
flashcards
Cells-Important Vocab
49
Updated 469d ago
0.0(0)
flashcards
GLW #2
20
Updated 185d ago
0.0(0)
flashcards
Personality
54
Updated 1127d ago
0.0(0)