Click Study Flashcards above to open the flashcard hub — hundreds of CCSP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the six official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CCSP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
CCSP Flashcard Study Modes
Flip mode lets you study one card at a time and check yourself, Match turns term-to-definition recall into a timed game, Type asks you to read a definition and type the term back, and Quiz builds multiple choice from the same 245 cards. Type is where a front like BYOK stops being familiar and starts being something you can actually produce.

Why Flashcards Work for the CCSP
Cloud Data Security carries the largest share at 20% and the largest stack at 50 cards. These drill the protection and lifecycle vocabulary you need on sight: cryptography terms such as AES and TLS, key custody distinctions like BYOK and HYOK, and data-control terms including DLP and IRM. Lifecycle cards such as Use phase and technique cards like Hashing sit alongside them.
Cloud Concepts, Architecture & Design holds 45 cards and 17%. The fronts cover service models, so PaaS, SaaS, and IaaS all appear separately, plus assurance and framework shorthand such as CSA CCM, CSA STAR, and CAIQ. Architectural terms like Container and Zero trust round out the foundation the rest of the deck builds on.
Cloud Application Security also sits at 17%, with 43 cards split between testing and identity. Code and traffic defense shows up as SAST, SCA, and WAF, while access control terms cluster around IAM, SSO, and MFA. Supporting cards such as PKI and DAM fill in the monitoring and trust pieces.
Cloud Platform & Infrastructure Security has 31 cards for another 17%, weighted toward resilience and virtualization risk. Recovery metrics dominate, with RTO, RPO, and RSL as separate fronts plus a comparison card, RTO vs RPO. Continuity terms like BCDR and Failover pair with virtualization threats such as VM escape and VM sprawl.
Cloud Security Operations brings 34 cards and 16%, covering operational tooling and forensic standards: SIEM, ITIL, and Honeypot, plus standard references like ISO/IEC 27037 and ISO/IEC 27050 alongside Log management. Legal, Risk & Compliance adds 42 cards at 13%, drilling privacy and audit language including PII, GDPR, and GAPP, contract terms such as SLA, and the audit report family SOC 1, SOC 2, and SOC 3.
The CCSP is dense with terminology — the data lifecycle, encryption and key management, virtualization, cloud IAM, standards, and compliance frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CCSP Flashcards by Domain
The cards are organized by the six official ISC2 domains. Cover them all, but start with the largest, Cloud Data Security:[1]
| Domain | Exam weight |
|---|---|
| Cloud Data Security | 20% |
| Cloud Concepts, Architecture & Design | 17% |
| Cloud Platform & Infrastructure Security | 17% |
| Cloud Application Security | 17% |
| Cloud Security Operations | 16% |
| Legal, Risk & Compliance | 13% |
How to Get the Most Out of These Flashcards
- Start with the heaviest stack. Cloud Data Security is 50 cards and 20% of the exam, so run it in Flip first until the encryption and key custody fronts feel automatic.
- Type the near-twins. Use Type mode on pairs that blur together, especially BYOK and HYOK, and on recovery metrics where RTO vs RPO decides the answer.
- Match the acronym families. Match is ideal for the audit and framework shorthand — SOC 1, SOC 2, and SOC 3, plus CSA CCM and CSA STAR — where speed matters more than depth.
- Move on when Quiz stops surprising you. Once a domain returns clean Quiz rounds twice in a row, shift to the practice test and let scenario questions expose the gaps flashcards cannot.
- Rotate rather than binge. With 245 cards across six domains, work one domain per sitting, then re-flip yesterday’s domain briefly before starting the next, and read the study guide for anything you keep missing.
CCSP Flashcards FAQ
Hundreds of free CCSP flashcards, organized across all six ISC2 domains — Cloud Concepts, Architecture & Design; Cloud Data Security; Cloud Platform & Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk & Compliance. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the CCSP's heavy terminology across data security, virtualization, IAM, and compliance.
All six ISC2 domains: Cloud Concepts, Architecture & Design (NIST characteristics, service models, shared responsibility); Cloud Data Security (lifecycle, encryption, tokenization, DLP); Cloud Platform & Infrastructure Security (virtualization, BCDR); Cloud Application Security (secure SDLC, IAM); Cloud Security Operations (SIEM, forensics); and Legal, Risk & Compliance.
Lead with Cloud Data Security (20%), the largest domain, then cover the rest — Domains 1, 3, and 4 are each 17%. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 exam outline effective October 1, 2025, covering all six domains in their official proportions.
CCSP flashcard bank
All 245 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Cloud Concepts, Architecture & Design (45)
- Shared responsibility model
Show answerHide answer
Security duties split between cloud provider and customer; the boundary shifts by service model, but data and access are always the customer's.
- Cloud computing (NIST definition)
Show answerHide answer
On-demand network access to a shared pool of configurable computing resources, rapidly provisioned and released with minimal management effort (NIST SP 800-145).
- Five essential characteristics of cloud
Show answerHide answer
On-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.
- On-demand self-service
Show answerHide answer
A consumer can provision computing capabilities automatically, without human interaction with the provider.
- Broad network access
Show answerHide answer
Capabilities are available over the network and accessed through standard mechanisms across diverse client devices.
- Resource pooling
Show answerHide answer
Provider resources are pooled to serve multiple consumers in a multi-tenant model, dynamically assigned and reassigned.
- Rapid elasticity
Show answerHide answer
Capabilities scale out and in quickly, appearing unlimited to the consumer and matching demand.
- Measured service
Show answerHide answer
Resource usage is metered and reported, enabling pay-per-use billing and optimization.
- IaaS
Show answerHide answer
Infrastructure as a Service — provider supplies compute, storage, and networking; customer manages the OS, runtime, and applications.
- PaaS
Show answerHide answer
Platform as a Service — provider supplies a managed platform/runtime; customer manages only the deployed application and its data.
- SaaS
Show answerHide answer
Software as a Service — provider delivers a fully managed application; customer manages only data and limited settings.
- Who secures most in IaaS vs SaaS?
Show answerHide answer
The customer secures the most in IaaS and the least in SaaS; the provider's share grows from IaaS to SaaS.
- Always the customer's responsibility
Show answerHide answer
Data classification and access management (IAM) — in every service model, regardless of provider.
- Always the provider's responsibility
Show answerHide answer
The physical infrastructure and the virtualization/hypervisor layer — in every service model.
- Public cloud
Show answerHide answer
Cloud infrastructure provisioned for open use by the general public.
- Private cloud
Show answerHide answer
Cloud infrastructure provisioned for the exclusive use of a single organization.
- Community cloud
Show answerHide answer
Cloud infrastructure shared by several organizations with common concerns (mission, security, compliance).
- Hybrid cloud
Show answerHide answer
A composition of two or more distinct clouds bound by technology enabling data and application portability.
- Multi-cloud
Show answerHide answer
Using cloud services from more than one provider, often to avoid lock-in or improve resilience.
- Cloud service provider (CSP)
Show answerHide answer
The entity that offers and operates cloud services.
- Cloud service customer (CSC)
Show answerHide answer
The entity that consumes cloud services.
- Cloud broker
Show answerHide answer
An intermediary that manages the use, performance, and delivery of cloud services and negotiates relationships.
- Cloud reference architecture
Show answerHide answer
A conceptual model describing cloud roles, activities, and functions (NIST SP 500-292).
- Virtualization
Show answerHide answer
Abstracting physical resources into virtual instances so one host can run many isolated workloads.
- Container
Show answerHide answer
OS-level virtualization packaging an app with its dependencies; shares the host kernel — lighter than a VM.
- Microservices
Show answerHide answer
An architecture that decomposes an application into small, independently deployable services.
- Serverless / FaaS
Show answerHide answer
An execution model where the provider fully manages infrastructure and code runs in response to events.
- Microsegmentation
Show answerHide answer
Fine-grained network isolation policies down to individual workloads; a building block of zero trust.
- Confidential computing
Show answerHide answer
Protecting data in use by processing it inside a hardware-based trusted execution environment (TEE).
- Edge computing
Show answerHide answer
Processing data near where it is generated to reduce latency and bandwidth use.
- Zero trust
Show answerHide answer
A model granting no implicit trust by network location; every request is authenticated, authorized, and continuously validated.
- Cloud secure design principles
Show answerHide answer
Build on the data lifecycle, BCDR planning, cost-benefit analysis, functional security requirements, and zero trust.
- Common Criteria (ISO/IEC 15408)
Show answerHide answer
An international standard for evaluating the security assurance of a product or system.
- FIPS 140-3
Show answerHide answer
The current U.S. federal standard for validating cryptographic modules (succeeding FIPS 140-2).
- CSA STAR
Show answerHide answer
CSA's Security, Trust, Assurance and Risk registry — provider self-assessment (CAIQ) and third-party certification.
- CSA CCM
Show answerHide answer
Cloud Controls Matrix — a vendor-neutral cloud security control framework mapped to major standards.
- CAIQ
Show answerHide answer
Consensus Assessments Initiative Questionnaire — a CSP self-assessment aligned to the CSA CCM.
- Evaluating a cloud provider
Show answerHide answer
Verify against criteria such as ISO/IEC 27017, Common Criteria, and FIPS 140-3, plus SOC 2 and CSA STAR.
- Tenancy isolation
Show answerHide answer
Keeping one tenant's data and workloads separated from others in a multi-tenant cloud — a core security goal.
- Vendor (cloud) interoperability
Show answerHide answer
The ability of cloud systems to work together and exchange data, reducing lock-in.
- Portability (cloud)
Show answerHide answer
The ability to move data and applications between providers without major rework.
- Reversibility (cloud)
Show answerHide answer
A customer's ability to retrieve data and terminate a service so the provider can no longer access it.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so one failure doesn't expose the asset.
- Multi-tenancy
Show answerHide answer
Many customers sharing the same physical resources with logical isolation between them.
- Service model and responsibility
Show answerHide answer
More control (IaaS) means more security responsibility; more convenience (SaaS) means less.
Cloud Data Security (50)
- Cloud secure data lifecycle
Show answerHide answer
Six phases: Create, Store, Use, Share, Archive, Destroy.
- Create phase
Show answerHide answer
Data is generated or modified; classify and label it as early as possible.
- Store phase
Show answerHide answer
Data committed to storage; apply encryption at rest and access controls.
- Use phase
Show answerHide answer
Data viewed or processed; enforce least privilege and information rights management.
- Share phase
Show answerHide answer
Data made available to others; control egress with DLP and protect transit with TLS.
- Archive phase
Show answerHide answer
Data moved to long-term retention; apply retention policy, encryption, and integrity checks.
- Destroy phase (cloud)
Show answerHide answer
Permanent removal; in the cloud this means crypto-shredding (destroying the keys).
- Volume storage
Show answerHide answer
Block storage attached to a VM like a virtual hard disk (IaaS).
- Object storage
Show answerHide answer
Storage of data as objects with metadata, accessed via API (e.g., buckets).
- Ephemeral storage
Show answerHide answer
Temporary storage tied to a running instance; lost when the instance stops.
- Structured vs unstructured data
Show answerHide answer
Structured fits a defined schema (databases); unstructured does not (documents, media).
- Encryption
Show answerHide answer
Transforming plaintext into ciphertext with an algorithm and key; reversible only with the key.
- Encryption at rest
Show answerHide answer
Protecting stored data so it is unreadable without the key.
- Encryption in transit
Show answerHide answer
Protecting data moving across networks, typically with TLS.
- Encryption in use
Show answerHide answer
Protecting data while processed, via confidential computing / trusted execution environments.
- Key management system (KMS)
Show answerHide answer
A system that generates, stores, rotates, and retires cryptographic keys.
- BYOK
Show answerHide answer
Bring Your Own Key — the customer generates or imports keys into the provider's KMS.
- HYOK
Show answerHide answer
Hold Your Own Key — the customer keeps and controls keys entirely outside the provider's environment.
- Key escrow
Show answerHide answer
Storing a copy of keys with a trusted third party for recovery or lawful access.
- Tokenization
Show answerHide answer
Replacing sensitive data with a non-sensitive token mapped to the real value in a separate secure vault.
- Tokenization vs encryption
Show answerHide answer
Tokenization swaps data for a vault-mapped token (no key on the data); encryption transforms data with a key.
- Data masking
Show answerHide answer
Substituting or scrambling data while preserving its format, typically for test/dev use.
- Anonymization
Show answerHide answer
Irreversibly removing identifiers so data can never be re-linked to an individual.
- Pseudonymization
Show answerHide answer
Replacing identifiers with pseudonyms that can be re-linked only with separate, protected information.
- Data obfuscation
Show answerHide answer
Umbrella term for hiding sensitive data (masking, anonymization, tokenization).
- Data dispersion
Show answerHide answer
Splitting data into fragments stored across locations (cloud RAID-like) for resilience.
- Bit splitting
Show answerHide answer
Dividing encrypted data into segments distributed across storage so no node holds usable data.
- Crypto-shredding
Show answerHide answer
Cryptographic erasure — making data unrecoverable by destroying its encryption keys.
- Data remanence (cloud problem)
Show answerHide answer
Residual data that may persist on shared media you cannot physically wipe — solved by crypto-shredding.
- DLP
Show answerHide answer
Data Loss Prevention — discover, monitor, and block unauthorized exfiltration of sensitive data.
- DLP three stages
Show answerHide answer
Discovery, monitoring, and enforcement.
- Data discovery
Show answerHide answer
Finding and locating sensitive data across structured, unstructured, and semi-structured stores.
- Data classification
Show answerHide answer
Categorizing data by sensitivity so the right protection, retention, and destruction rules apply.
- Data labeling
Show answerHide answer
Tagging data with classification and handling metadata.
- IRM
Show answerHide answer
Information Rights Management — persistent access and usage controls bound to a data object wherever it travels.
- Data retention policy
Show answerHide answer
Rules for how long data must be kept before deletion or archiving.
- Legal hold
Show answerHide answer
Suspending normal deletion to preserve data relevant to litigation or investigation.
- Auditability of data events
Show answerHide answer
Logging data events to provide traceability, accountability, and nonrepudiation.
- Chain of custody
Show answerHide answer
Documented handling of evidence that preserves its integrity and legal admissibility.
- Nonrepudiation
Show answerHide answer
Assurance that an actor cannot deny having performed an action.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest used to verify integrity.
- Data sovereignty
Show answerHide answer
The principle that data is subject to the laws of the country where it is stored.
- Data residency
Show answerHide answer
The physical or geographic location where data is stored.
- Symmetric encryption
Show answerHide answer
Uses one shared secret key for both encryption and decryption (e.g., AES); fast.
- Asymmetric encryption
Show answerHide answer
Uses a public/private key pair (e.g., RSA, ECC); solves key exchange and enables signatures.
- AES
Show answerHide answer
Advanced Encryption Standard — the dominant symmetric block cipher used for cloud data at rest.
- TLS
Show answerHide answer
Transport Layer Security — the protocol that protects data in transit (HTTPS).
- Data flow mapping
Show answerHide answer
Documenting how data moves through systems to find where to apply controls.
- Tokenization use case
Show answerHide answer
Common for payment card (PAN) data because the token carries no exploitable value if stolen.
- Encryption key rotation
Show answerHide answer
Periodically replacing keys to limit exposure if a key is compromised.
Cloud Platform & Infrastructure Security (31)
- Cloud infrastructure components
Show answerHide answer
Physical environment, network and communications, compute, virtualization, storage, and the management plane.
- Management plane
Show answerHide answer
The centralized console/API to provision and control cloud resources — the highest-value target.
- Why protect the management plane
Show answerHide answer
Compromising it can give an attacker control of the entire cloud environment at once.
- Hypervisor
Show answerHide answer
Software that creates and runs virtual machines, allocating host resources to guests.
- Type 1 hypervisor
Show answerHide answer
Bare-metal — runs directly on hardware, no host OS; smaller attack surface; used in production cloud.
- Type 2 hypervisor
Show answerHide answer
Hosted — runs atop a host OS; larger attack surface; used for desktop labs.
- More secure hypervisor type
Show answerHide answer
Type 1 (bare-metal), because there is no host OS to compromise.
- VM escape
Show answerHide answer
An attack where a guest VM breaks isolation to reach the hypervisor or host, threatening other tenants.
- VM sprawl
Show answerHide answer
Uncontrolled growth of virtual machines, increasing attack surface and management burden.
- Container security risk
Show answerHide answer
Containers share the host kernel, so a kernel compromise can affect all containers on the host.
- Compute security
Show answerHide answer
Securing the processing resources (CPU/memory) allocated to workloads.
- Storage security (infrastructure)
Show answerHide answer
Protecting the storage layer with encryption, access control, and isolation.
- Network security (cloud)
Show answerHide answer
Securing communications with segmentation, firewalls, and encryption in transit.
- Data center tiers
Show answerHide answer
Uptime Institute Tiers I–IV rate data-center redundancy and availability (IV = highest).
- HVAC in data center design
Show answerHide answer
Heating, ventilation, and air conditioning maintain environmental conditions for reliability.
- Logical vs physical design
Show answerHide answer
Logical design defines structure/relationships; physical design defines actual hardware and layout.
- Risk assessment (infrastructure)
Show answerHide answer
Identify, analyze, and mitigate cloud-specific threats, vulnerabilities, and attacks.
- Security controls (cloud platform)
Show answerHide answer
Physical/environmental, system/communication, virtualization protection, IAM, and audit mechanisms.
- Audit mechanisms (infrastructure)
Show answerHide answer
Log collection, log correlation, and packet capture for monitoring and investigation.
- BCDR
Show answerHide answer
Business Continuity and Disaster Recovery — plans to maintain and restore operations after a disruption.
- RTO
Show answerHide answer
Recovery Time Objective — the maximum acceptable time to restore a process after a disruption.
- RPO
Show answerHide answer
Recovery Point Objective — the maximum acceptable data loss measured backward in time; drives backup frequency.
- RSL
Show answerHide answer
Recovery Service Level — the percentage of full compute capacity a process needs during a disaster.
- RTO vs RPO
Show answerHide answer
RTO = time to recover; RPO = how much data you can afford to lose.
- BCDR strategy steps
Show answerHide answer
Define business requirements, create the strategy, implement it, and test it.
- High availability (HA)
Show answerHide answer
Designing systems to remain operational despite component failures.
- Clustering
Show answerHide answer
Linking servers so they act as one system for availability and load distribution.
- Redundancy
Show answerHide answer
Duplicating components so a failure does not cause an outage.
- Failover
Show answerHide answer
Automatically switching to a standby system when the primary fails.
- Cloud bursting
Show answerHide answer
Using public cloud capacity to handle demand spikes beyond a private cloud's capacity.
- Tenant isolation failure
Show answerHide answer
A breakdown in separation that lets one tenant access another's data or workloads.
Cloud Application Security (43)
- Secure SDLC
Show answerHide answer
Building security into every phase of software development rather than testing for it at the end.
- Secure SDLC phases
Show answerHide answer
Requirements/training, design, develop, test, deploy, operate/maintain.
- Threat modeling
Show answerHide answer
Systematically identifying and prioritizing threats to a system during design.
- STRIDE
Show answerHide answer
Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
- DREAD
Show answerHide answer
A risk-rating model: Damage, Reproducibility, Exploitability, Affected users, Discoverability.
- PASTA
Show answerHide answer
Process for Attack Simulation and Threat Analysis — a risk-centric threat-modeling methodology.
- SAST
Show answerHide answer
Static Application Security Testing — analyzing source or binary code without executing it.
- DAST
Show answerHide answer
Dynamic Application Security Testing — testing a running application from the outside.
- IAST
Show answerHide answer
Interactive AST — instrumenting a running app to combine static and dynamic analysis.
- SCA
Show answerHide answer
Software Composition Analysis — identifying open-source components and their known vulnerabilities.
- SAST vs DAST
Show answerHide answer
SAST inspects code early; DAST tests the running app for runtime/config flaws.
- OWASP Top 10
Show answerHide answer
A community list of the most critical web application security risks.
- SANS Top 25
Show answerHide answer
A list of the most dangerous software errors (CWE).
- Input validation
Show answerHide answer
Checking and sanitizing all input to prevent injection and other attacks — never trust user input.
- SQL injection
Show answerHide answer
Inserting malicious SQL via unvalidated input to read or alter a database.
- OWASP ASVS
Show answerHide answer
Application Security Verification Standard — a framework of security requirements for testing apps.
- Software supply-chain security
Show answerHide answer
Securing third-party, open-source, and vendor components and their provenance.
- Verified secure software
Show answerHide answer
Using approved, validated APIs and components from trusted sources.
- Sandboxing
Show answerHide answer
Isolating execution so untrusted code cannot affect the wider system.
- Application virtualization
Show answerHide answer
Running an application in an isolated environment abstracted from the OS.
- Orchestration
Show answerHide answer
Automating the deployment, scaling, and management of containers/workloads (e.g., Kubernetes).
- WAF
Show answerHide answer
Web Application Firewall — filters and monitors HTTP traffic to protect web applications.
- API gateway
Show answerHide answer
A managed entry point enforcing authentication, rate limiting, and routing for APIs.
- DAM
Show answerHide answer
Database Activity Monitoring — real-time monitoring of database transactions.
- XML firewall
Show answerHide answer
A device/service that inspects and filters XML traffic to protect web services.
- IAM
Show answerHide answer
Identity and Access Management — the framework for managing digital identities and access rights.
- Federated identity
Show answerHide answer
Linking a user's identity across multiple systems or organizations.
- Identity provider (IdP)
Show answerHide answer
A service that authenticates users and issues identity assertions to relying parties.
- SSO
Show answerHide answer
Single Sign-On — one authentication grants access to multiple systems.
- MFA
Show answerHide answer
Multi-Factor Authentication — verifying identity with two or more independent factors.
- SAML
Show answerHide answer
An XML-based standard for federated authentication and web single sign-on.
- OAuth 2.0
Show answerHide answer
An authorization framework granting an app delegated access to resources without sharing credentials.
- OpenID Connect (OIDC)
Show answerHide answer
An authentication layer built on OAuth 2.0 that adds identity (who the user is).
- SAML vs OAuth vs OIDC
Show answerHide answer
SAML and OIDC handle authentication; OAuth 2.0 alone handles authorization (delegated access).
- CASB
Show answerHide answer
Cloud Access Security Broker — a policy enforcement point giving visibility, compliance, data security, and threat protection.
- CASB four pillars
Show answerHide answer
Visibility, compliance, data security, and threat protection.
- Secrets management
Show answerHide answer
Securely storing and controlling access to credentials, keys, and tokens used by applications.
- Cryptographic agility
Show answerHide answer
Designing systems so cryptographic algorithms can be swapped without major rework.
- PKI
Show answerHide answer
Public Key Infrastructure — the framework of certificate authorities and certificates that manages public keys.
- Digital signature
Show answerHide answer
A hash encrypted with the signer's private key, providing integrity, authenticity, and nonrepudiation.
- Least privilege
Show answerHide answer
Granting only the minimum access needed to perform a task, and nothing more.
- Separation of duties
Show answerHide answer
Splitting a sensitive task so no single person can complete it alone.
- Abuse-case testing
Show answerHide answer
Testing how an application behaves under intentional misuse, not just normal use.
Cloud Security Operations (34)
- BIOS/UEFI hardening
Show answerHide answer
Securing firmware settings to reduce the attack surface of a host before the OS loads.
- TPM
Show answerHide answer
Trusted Platform Module — a hardware chip that stores keys and supports host attestation.
- Host attestation
Show answerHide answer
Verifying the integrity and trust state of a host before extending trust to it.
- OS hardening (baselines)
Show answerHide answer
Configuring an OS to a secure baseline by removing unneeded services and applying secure settings.
- Patch management
Show answerHide answer
Identifying, testing, and applying updates to fix vulnerabilities promptly.
- Infrastructure as code (IaC)
Show answerHide answer
Defining and provisioning infrastructure through machine-readable config files for consistency.
- Jumpbox (bastion host)
Show answerHide answer
A hardened intermediary host used to access systems in a protected network.
- Secure shell (SSH)
Show answerHide answer
An encrypted protocol for secure remote administration.
- RDP
Show answerHide answer
Remote Desktop Protocol — remote GUI access that must be secured (MFA, restricted exposure).
- Scalability (operations)
Show answerHide answer
The ability to grow or shrink capacity to meet demand while remaining available.
- ITIL
Show answerHide answer
A framework of IT service management best practices used to run cloud operations.
- ISO/IEC 20000-1
Show answerHide answer
The international standard for an IT service management system.
- Change management
Show answerHide answer
Evaluating, approving, and documenting changes — prevents most cloud incidents.
- Configuration management
Show answerHide answer
Tracking the state and relationships of assets across the environment.
- Release & deployment management
Show answerHide answer
Controlling repeatable, low-risk rollouts of changes.
- Problem management
Show answerHide answer
Identifying and eliminating the root causes of recurring incidents.
- Incident management
Show answerHide answer
Detecting, responding to, and recovering from security/operational events.
- Service-level management
Show answerHide answer
Defining, meeting, and reporting on service-level agreements (SLAs).
- Availability management
Show answerHide answer
Ensuring services meet agreed availability targets.
- Capacity management
Show answerHide answer
Ensuring sufficient resources to meet current and future demand.
- SOC (Security Operations Center)
Show answerHide answer
The team and function that monitors and responds to security events.
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs for detection and investigation.
- Log management
Show answerHide answer
Collecting, retaining, and protecting logs to support detection and forensics.
- Digital forensics (cloud)
Show answerHide answer
Collecting and analyzing evidence in the cloud, where you don't control the physical media.
- ISO/IEC 27037
Show answerHide answer
Guidelines for identification, collection, acquisition, and preservation of digital evidence.
- ISO/IEC 27050
Show answerHide answer
Standard for electronic discovery (eDiscovery).
- Evidence management
Show answerHide answer
Handling evidence to preserve integrity and an unbroken chain of custody.
- Vulnerability assessment
Show answerHide answer
Scanning systems to identify and prioritize known weaknesses.
- Communication with relevant parties
Show answerHide answer
Coordinating with vendors, customers, partners, regulators, and stakeholders during operations and incidents.
- Cloud forensics challenge
Show answerHide answer
Multi-tenancy, data location, and provider dependence make evidence collection complex.
- Baseline (security)
Show answerHide answer
A documented minimum secure configuration applied consistently across systems.
- Honeypot
Show answerHide answer
A decoy system used to detect, deflect, or study attackers.
- Logging time synchronization
Show answerHide answer
Synchronizing clocks (e.g., NTP) so correlated logs have consistent, comparable timestamps.
- Continuous monitoring
Show answerHide answer
Ongoing assessment of security controls and posture to detect drift and threats.
Legal, Risk & Compliance (42)
- Conflicting international legislation
Show answerHide answer
Different countries' laws can impose contradictory obligations on cloud data — a key legal risk.
- GDPR
Show answerHide answer
The EU General Data Protection Regulation governing the processing of personal data.
- Data controller
Show answerHide answer
Under GDPR, the entity that decides why and how personal data is processed.
- Data processor
Show answerHide answer
Under GDPR, a party that processes personal data on the controller's instructions (often the CSP).
- PII
Show answerHide answer
Personally Identifiable Information — data that can identify an individual.
- Regulated PII
Show answerHide answer
Personal data protected by law (e.g., HIPAA, GDPR) with statutory penalties for breach.
- Contractual PII
Show answerHide answer
Personal data protected because a contract requires it (e.g., PCI DSS), with contractual consequences.
- Regulated vs contractual PII
Show answerHide answer
Regulated PII is mandated by law; contractual PII is mandated by agreement.
- ISO/IEC 27018
Show answerHide answer
A code of practice for protecting PII in public clouds acting as PII processors.
- GAPP
Show answerHide answer
Generally Accepted Privacy Principles — a privacy management framework.
- Privacy Impact Assessment (PIA)
Show answerHide answer
A structured assessment of the privacy risks of a system or process.
- eDiscovery
Show answerHide answer
Identification, collection, and production of electronically stored information for legal matters.
- SOC 1
Show answerHide answer
An attestation report on controls relevant to financial reporting.
- SOC 2
Show answerHide answer
A report on controls for security, availability, processing integrity, confidentiality, and privacy.
- SOC 3
Show answerHide answer
A public, summary version of a SOC 2 report with no sensitive detail.
- SOC 2 Type I vs Type II
Show answerHide answer
Type I tests control design at a point in time; Type II tests operating effectiveness over a period.
- Which SOC report for a CSP?
Show answerHide answer
SOC 2 — customers request it to assess a provider's security and privacy controls.
- SSAE 18 / ISAE 3402
Show answerHide answer
Attestation standards under which SOC 1 reports are produced.
- Gap analysis
Show answerHide answer
Comparing current controls against a required standard to find shortfalls.
- Internal vs external audit
Show answerHide answer
Internal audit is performed by the organization; external audit by an independent third party.
- ISMS
Show answerHide answer
Information Security Management System — a governed framework of policies and controls (ISO/IEC 27001).
- ISO/IEC 27001
Show answerHide answer
The international standard for an Information Security Management System.
- Right to audit
Show answerHide answer
A contract clause letting the customer assess a provider's controls (often satisfied by SOC 2 / ISO certs).
- SLA
Show answerHide answer
Service Level Agreement — a contractual commitment on service performance and availability metrics.
- Vendor lock-in
Show answerHide answer
Difficulty migrating away from a provider due to proprietary dependencies.
- Cloud contract key clauses
Show answerHide answer
Right to audit, SLAs/metrics, data access/location, termination, litigation, insurance, and assurance.
- Risk treatment options
Show answerHide answer
Avoid, mitigate, transfer/share, or accept the risk.
- Risk appetite
Show answerHide answer
The amount of risk an organization is willing to accept in pursuit of its objectives.
- Risk profile
Show answerHide answer
An organization's overall exposure to risk across its assets and activities.
- ISO 31000
Show answerHide answer
An international standard providing principles and guidelines for risk management.
- NIST RMF
Show answerHide answer
The NIST Risk Management Framework for selecting, implementing, and monitoring controls.
- ENISA
Show answerHide answer
The European Union Agency for Cybersecurity, which publishes cloud risk guidance.
- Distributed IT model impact
Show answerHide answer
Spreading control across a provider changes accountability and complicates risk management.
- Supply-chain management (ISO/IEC 27036)
Show answerHide answer
Managing information security risk in supplier and outsourcing relationships.
- Cyber risk insurance
Show answerHide answer
Insurance that transfers some financial impact of a cyber incident to an insurer.
- Customer remains accountable
Show answerHide answer
Even when a provider holds the data, the customer stays accountable for protecting it.
- Provider risk-program assessment
Show answerHide answer
Evaluating a provider's controls, methodologies, policies, risk profile, and risk appetite.
- FedRAMP
Show answerHide answer
A U.S. government program standardizing the security assessment and authorization of cloud services.
- Forensic requirements (legal)
Show answerHide answer
Contractual and legal obligations for collecting and preserving cloud evidence.
- Cloud audit scope restriction
Show answerHide answer
Providers often limit what a customer audit can cover, hence reliance on third-party reports.
- Termination clause (contract)
Show answerHide answer
Defines how a relationship ends and how data is returned or destroyed, reducing lock-in.
- Geofencing data
Show answerHide answer
Restricting where data may be stored or accessed to meet residency/sovereignty rules.
References
- 1.ISC2. “CCSP Certification Exam Outline (effective October 1, 2025).” isc2.org. ↑
- 2.ISC2. “CCSP — Certified Cloud Security Professional.” isc2.org. ↑
- 3.Cloud Security Alliance. “Security Guidance for Critical Areas of Focus in Cloud Computing v4.0.” cloudsecurityalliance.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
