CDL - Security Flashcards
What are the 5 key GCP security products?
- IAM
- Cloud Identity
- BeyonCorp Enterprise
- Identity-Aware Proxy
- Managed Services for Microsoft Active Directory
What is GCP Cloud Identity?
The management of user identities, devices, and applications from one console.
What is GCP IAM?
The establishment of fine-grained identity (role creation) and access management (role access) from the GCP console.
What is GCP Identity-Aware Proxy?
Service that allows you to use identity and context to guard access to your applications and VMs
What is BeyondCorp Enterprise?
GCPs zero-trust solution that 1) enables secure access and 2) integrated data threat protection
What is Managed Service for Micosoft AD? (?)
The use of a highly available, hardened service running Microsoft AD
What is GDPR? (exam)
General Data Protection Regulation - An EU privacy law applied to entities that collect and analyze data tied to EU residents.
What is GCP Compliance Reports Manager?
Put simply, they are downloadable PDFs that demonstrate that GCP is compliant with various compliance and security standards.
What is ISO & ISE?
International organization for Standardization +
International Electrotechnical Commission
What are the different ISO/ESI compliance standards?
ISO/ESO
27001 - control of implementation guidance (exam )
27017 - enhanced focused on cloud security
27018 - protection of personal data in the cloud (PII)
27701 - Privacy Information Management System (PIMS) framework that outlines controls and processes to manage data privacy and protect PHII
What is SOC?
System and Organization Controls
What is SOC 2?
Evaluates internal controls, policies, and procedures that directly relate to the security of a system at a service organizations.
What is FIPS 140-2? (exam)
Stands for Federal Information Processing Center that sets security standards and requirements for cryptographic modules.
Note: FIPS 140-3 is better and more secure.
What is HIPPA?
Health Insurance Portability and Accountability Act - Law that regulates PII
What is FedRAMP? (exam)
Federal Risk and Authorization Management Program.
US Gov standardized approach to security authorizations for CSP.
In an effort to remain transparent, what are Google’s Trust Principles?
What are GCPs Privacy Practices?
What is DDoS?
Distributed Denial of Service.
A malicious attack that floods a website with large amounts of traffic.
What is Cloud Armor? What are its two billing options?
It is a DDoS and Web Application Firewall (WAF) service.
- PAYG
- Managed Protection Plus (3k monthly)