Cloudy Concepts
Security Savvy
Change Champions
Data Defenders
Resilient Resources
100

The computing architecture where on-demand resources are billed based on metered utilization.

What is cloud computing?

100

A scheme for identifying vulnerabilities developed by MITRE and adopted by NIST.

What is Common Vulnerabilities and Exposures (CVE)?

100

The process by which the need for change is recorded and approved.

What is change control?

100

An asset disposal technique that ensures data remnants are rendered physically inaccessible.

What is destruction?

100

A predetermined alternate location where a network can be rebuilt after a disaster.

What is a cold site?

200

A system that classifies the ownership and management of a cloud as a public, private, community, or hybrid.

What is a cloud deployment model?

200

The risk management approach to quantifying vulnerability data.

What is the Common Vulnerability Scoring System (CVSS)?

200

The process through which changes to the configuration of information systems are implemented.

What is change management?

200

An asset disposal technique that relies on a third-party to use sanitization or destruction methods.

What is certification?

200

A fully configured alternate processing site that can be brought online quickly after a disaster.

What is a hot site?

300
The classifications of cloud services based on the limit of the providers responsibility.

What are the cloud service models?

300

The process of investigating, collecting, analyzing, and disseminating information about emerging threats.

What is cyber threat intelligence (CTI)?

300

The process through which an organizations information systems components are kept in a controlled state.

What is a configuration management?

300

A scan that uses credentials to take a deep dive during the vulnerability scan.

What is a credentialed scan?

300
A resiliency mechanism where processing and data storage resources are replicated between physically distant sites.

What is geographic dispersion?

400

The term for enterprise management software that mediates access to cloud services.

What is a cloud access security broker (CASB)?

400

A malicious script hosted on an attacker's site designed to compromise clients browsing a trusted site.

What is cross-site scripting (XSS)?

400

The software code or security research that remains in the ownership of the developer.

What is closed/proprietary?
400

A temporary DNS record that redirects malicious traffic to a controlled IP address.

What is a DNS sinkhole?

400

A technique that ensures a redundant component can take over the functionality of a failed asset.

What is failover?

500

Organizations that provide infrastructure, application, and/or storage services via a subscription-based, cloud-centric offering.

What are cloud service providers (CSPs)?

500

The term for resources on the Internet that are protected from general access by multiple layers of encrypting and routing.

What is the dark web?

500

The operating system virtualization deployment containing everything required to run a service or application.

What is containerization?

500

A deception strategy that returns spoofed data in response to network probes.

What is fake telementry?

500

The security strategy that positions layers of diverse security control categories and functions.

What is defense in depth?
M
e
n
u