CCSP Domain 3: Cloud-Specific Risks Flashcards

1
Q

The cloud security alliance details the top cloud-specific security threats in what document?

A

The CSA Egregious 11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What threats does The CSA Egregious 11 contain?

A
  1. data breaches
  2. misconfigured and inadequate change control
  3. lack of cloud security architecture and strategy
  4. insufficient identity, credential access and key management
  5. account hijacking
  6. insider threat
  7. insecure interfaces and APIs
  8. weak control plane
  9. “metastructure” and “applistructure” failures
  10. limited cloud usage visibility
  11. abuse and nefarious use of cloud services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a data breach?

A

loss of sensitive data (PI, PII, PHI, IP) due to a security breach, that is intentional and malicious

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a data leak?

A

unintentional loss/oversharing of sensitive data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which controls help to mitigate insecure interfaces and APIs?

A

MFA, RBAC, key-based access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is metastructure?

A

protocols and mechanisms that provide the interface between the cloud layers, enabling management and configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is applistructure?

A

applications deployed in the cloud and the underlying application services used to build them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is applistructure and metastructure failures?

A

vulnerabilities in the operational capabilities that CSPs make available, like APIs for accessing various cloud services; if CSPs inadequately secure these interfaces, any resulting solutions built on top of those services will inherit these weaknesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly