C90.07A: Fundamental Cloud Security (only abbreviations) Flashcards
A I C T
Availability | Integrity | Confidentiality | Trust
= Cloud Security Basics
I A M
Identify and Access Management
= Identity in the cloud, User management, Authentication and Authorization
D o S
Denial Of Service
= Access oriented cloud threat
S T R I D E
Spoofing | Tempering | Repudiation | Information disclosure | Denial of service | Elevation of Privilege
= Security threat categories
A D C
Application Delivery Controller
N P E
Non Person Entities
P E
Person Entities
A P I
Application Programm Interface
= an NPE
D L P
Data Loss Protection
= part of ADC mechanism
T L S
Transport Layer Security
= part of ADC mechanism
D D o S
Distributed Denial Of Service
= part of ADC mechanism
D N S
Domain Name Service
= mapping network of servers domain names to IP address
I D P S
Intrusion Detection and Prevention System
= automated process
monitoring, identify incidents, log information, stop processes and report to administrators
P K I
Public Key Infrastructure
= data file, binding information user id, signature from issuing authority and have corresponding private key.
Also called: digital certificate, X.509 certificate or public key certificate
C R L
Certificate Revocation List
C A
Certificate Authority
= part of Certificate Trust Store mechanism
V P N
Virtual Private Network
L 2 T P
Layer Two Tunneling Protocol
= used to ensure privacy with VPN, data is encrypted at sending side and decrypted and receiving side
V P C
Virtual Private Cloud
= segmentation of public cloud service provider’s multi-tenant environment to support private cloud computing.
combined with VPN p[rovides secure data trabnsfer between on-premise and public cloud, ensuring isolated boundaries
C C G
Cloud Consumer Gateway
= hard- or software appliance on consumer premises that serves as a bridge between local and remote networks
V M
Virtual Machine
V I M
Virtual Infrastructure Manager
L U N
Logical Unit Number
= a unique identifier for designating an individual or collection of physical or virtual storage devices that execute input/output (I/O) commands
S I E M
Security Information and Event Management