Comprehend Cloud Infrastructure Components
Design a Secure Data Center
Analyze Risks Associated with Cloud Infrastructure and Platforms
Plan and Implementation of Security Controls
Plan Business Continuity (BC) and Disaster Recovery (DR)
100

What encompasses the actual data centers, servers, hardware, and facilities and forms the foundational layer of cloud security.

Physical Environment

100

In a cloud environment it replaces physical infrastructure with software-defined controls

Logical Design

100

The systematic process of evaluating the cloud infrastructure, applications, and data to identify vulnerabilities, quantify threats, and prioritize security measures.

Risk Assessment

100

Deployment model in which the customer has physical security responsibility

Private On-Premise

100

The two parameters which have to be defined to ensure an effective cloud BC/DR strategy

Recovery Time Objective (RTO) and Recovery Point Objective (RPO)

200

It represents the foundational nervous system of cloud infrastructure.

Network and communications

200

It implements a defense-in-depth model utilizing secured perimeters, facility shell hardening, restricted data halls, and granular rack-level access controls.

Physical design

200

The process of discovering and documenting all cloud assets.

Identification

200

The best method of data deletion for CSP stored data which is at the CSP location.

Cryptographic Erase/Crypto-shredding

200
One of the major reasons why cloud-to-back home is not a good BC/DR strategy.

Capacity

300

Operates at the subnet level as the first layer of defense, using rule-based stateless packet filtering to allow or deny traffic

Network Access Control Lists (NACLs)

300

In a secure data center, it protects the physical-to-logical boundary.

Environmental design

300

Defining threat scenarios using methodologies like STRIDE to identify spoofing, tampering, and denial of service across the customers architecture.

Threat mapping

300

The recommended version of encryption for data-in-transit.

TLS 1.3

300

Maintained and isolated write-once-read-many backups to prevent ransomware or rogue administrators from deleting historical data.

Immutable backups

400

It abstracts physical hardware into software-based logical pools.

Virtualization

400

It requires the integration of fault tolerance, zero-trust access, and automated infrastructure to ensure continuous operation under stress.

Design resilience

400

Specific weaknesses or flaws in cloud infrastructure, platforms, or applications.

Vulnerabilities

400

The recommended version of data encryption for data-at-rest.

AES256

400

The process where Recovery Time Objective and Recovery Point Objective are determined.

Business Impact Analysis (BIA)

500

The central command center used to orchestrate and configure the cloud infrastructure.

Management Plane

500

It involves utilizing multiple, redundant ISPs with cables entering a data center from distinct geographical points.

Multi-vendor pathway connectivity

500

An acronym used to identify negative risk treatment options.

MATA,  Mitigate, Accept, Transfer, Avoid

500

The recommended control for data-in-use.

Digital Rights Management (DRM)

500

The type of plan testing which requires production to be shut down completely.

Full-interruption testing