Describe Cloud Data Concepts
Design and Implement Cloud Data Storage Architectures
Design and Apply Data Security Technologies and Strategies
Implement Data Discovery
Plan and Implement Data Classification
100

The data lifecycle phase which focuses on implementing encryption at rest, data redundancy, and secure access controls across cloud storage.

Store

100

Cloud storage type that requires data immutability, stringent access controls and encryption.

Long-term storage

100

A process used to check the integrity of a received data file.

Hashing

100

The process of identifying, inventorying, and mapping data across an organization's systems.

Data discovery

100

According to NIST SP 800-39, the two classifications which are most important for data classification

Sensitivity and Criticality

200

A cloud security technique that fragments, encodes, and distributes encrypted data slices across multiple disjointed servers.

Data dispersion

200

Temporary, non-persistent data volumes, local disk storage, or memory which automatically wipes when an instance terminates.

Ephemeral storage

200

A process used to obscure data and make it unreadable without the appropriate tools.

Encryption

200

A method that uses attached tags to locate, categorize, and govern datasets across cloud environments.

Label-based data discovery

200

The role responsible for doing data classification.

Data owner

300

A tool that can help visualize data movement to aid organizations in better understanding their data flows and broader data lifecycles processes.

Data Flow Diagram

300

A distributed architecture for unstructured data.

Object storage

300

A process used to ensure data integrity and authenticity of sender.

Digital Signature

300

A process of creating data about data for the purpose of data discovery.

Metadata-based data discovery

300

The role responsible for implementing the controls associated with the data classification.

Data custodian

400

Data lifecycle phase which executes secure erasure.

Destroy

400

Storage type that acts as a virtual hard drive attached to a virtual machine or container.

Volume storage

400

A symmetric process used to provide digital signature like capability.

HMAC

400

A method of analyzing the actual data payload to locate, classify and understand assets within cloud environments.

Content-based data discovery

400

The sub-category of commercial data classification which is used for data which gives the company its competitive edge.

Proprietary

500

Data lifecycle phase which includes viewing, processing, or dynamic analysis.

Use

500

SQL injection is an attack against what type of storage

Database

500

A non-encryption technique which can be used to satisfy PCI-DSS encryption requirements.

Tokenization

500

The data type that typically accounts for over 80% of data in the enterprise.

Unstructured

500

The foundational blueprint for cloud data security bridging the gap between data discovery and actual classification.

Data mapping