
Explore cloud architectural concepts, definitions of cloud computing, service categories, deployment models, multi-tenancy and oversubscription, roles and responsibilities, virtualization, emerging technologies, and hands-on quizzes and labs.
Define cloud computing as on-demand, network-accessible resources with self-service and rapid elasticity. Learn to provision VPCs, subnets, NAT, EC2 instances, auto scaling, security groups, and measured or metered service.
Explore the five cloud deployment models—public, private, community, hybrid, and multicloud—and learn how ownership, access, security, and cost shape cloud infrastructure decisions.
Virtualization enables rapid provisioning of virtual machines and scalable resources for agile cloud computing. Hypervisors manage resource pools across bare metal and hosted configurations, enabling secure isolation and self-service provisioning.
Explore service level agreements with cloud providers, detailing performance parameters, negotiations, and penalties. Learn how availability, service credits, and capacity planning relate to elasticity and scalability.
Explore how the cloud shared responsibility model splits security duties between customers and providers, detailing service-specific roles for EC2, RDS, and S3, data encryption, cross-account audits, and compliance evidence.
Explore how cloud governance uses policies, processes, and guardrails to guide cloud adoption, enforce compliance, and optimize spending with automated controls like AWS Control Tower and Account Factory.
Outsource cloud computing tasks to a cloud service provider to manage IT infrastructure and services, boosting efficiency and cost effectiveness while risking visibility, control, privacy, and regulatory concerns like GDPR.
Explore the internet of things (IoT) and its security challenges, including device credentials and TLS protection for data moving to AWS IoT, essential for cloud security professionals.
Bring processing closer to data sources with edge and fog computing to enable real-time analysis. Leverage confidential computing with trusted execution environments to protect data in memory.
Explore cloud service offerings, multi-tenancy concepts, and cloud deployment models through CCSP definitions, analyzing a provider-created virtual server scenario to identify the deployment model used.
Analyze data sanitisation options for ssds, comparing secure erase, data overwriting, and cryptographic erasure, with emphasis on key management for secure reuse of drives.
Evaluate virtualization with hypervisors, containers, and serverless computing to bundle workloads, move them across operating systems, and achieve isolation, scalability, and cost efficiency in cloud environments.
Explore the cloud reference architecture defined by ISO 17789, detailing the three roles: cloud service customer, cloud service provider, and cloud service partner, and their 15 subroles with activities.
Understand and describe the differences between the various security approaches or strategies
Compare zero trust architecture, which continuously verifies identity, devices, and context to adapt access. Contrast perimeter-based security that relies on one-time authentication and policies with multifactor authentication and continuous monitoring.
Discover how type one hypervisors enhance security with reduced attack surfaces and stronger isolation, compared to type two, while improving resource efficiency and deployment use cases.
Explore security controls for securing communications and infrastructure, including network security groups and bastion hosts, to restrict internet-facing ports on cloud servers within zero trust architectures.
Explore instance level security groups and subnet level network access control lists for AWS EC2 and Azure VMs, and highlight stateful versus stateless traffic controls and interface level rules.
Define the need for vulnerability assessments as a systematic process to identify vulnerabilities. Regulations like PCI DSS drive assessment frequency to protect confidentiality, integrity, and availability.
Use a bastion server as a gateway to isolate internal resources and enforce access controls. Demonstrate SSH tunneling to a MySQL database and rotating credentials with AWS Secrets Manager.
Design robust backup strategies with full, incremental, and differential backups, meet recovery point objectives, enforce encryption and retention and lifecycle management, and test restorations for rapid, compliant long-term data protection.
Explore the CSA's egregious 11, the top cloud security threats, and learn best practices to identify, assess, and mitigate them for CCSP professionals in line with regulatory standards.
Explore how data breaches cause unauthorized access to data, causing exposure, loss, and theft of customer data, and map threats to the Cloud Controls Matrix with encryption and access controls.
Misconfiguration of cloud assets, including unsecured data storage, excessive permissions, and default settings, drives data breaches and service disruption, while weak change control undermines configuration management and security assessment.
Learn how insufficient identity, credential, access, and key management causes data breaches, and implement multifactor authentication, least privilege, key rotation, and Secrets Manager via AWS KMS to secure resources.
Explore data creation from human inputs, IoT sensors, and applications, producing text, numbers, images, or audio, and apply security by design and privacy by design.
Learn the data store phase, selecting storage systems, organizing data, and enforcing security, integrity, backups, recovery, retention, indexing, and auditing to protect and access data.
Explore how the data use phase actively utilizes data to drive insights and support operations. Secure API and database access through authentication, authorization, and encryption.
Explore securely sharing data within and outside an organization, using Macie to discover sensitive data, query results with Athena, and visualize findings in QuickSight.
Explore the need for identity and access management by examining how automation, policy enforcement, and audit trails secure access across cloud, mobile, and diverse apps to meet compliance.
Explore user access, privileged access, and service access within identity and access management, with real-world examples and Unix file permissions that show how roles govern access.
Explore the CIA triad by examining how confidentiality, integrity, and availability form core information security goals and how security controls address them. Upcoming tutorials describe each principle in detail.
Ensure confidentiality by restricting access to data and resources for authorized subjects through strict access control, encryption, authentication, and data classification, supported by training and privacy practices.
Understand how identity, authentication, authorization, and accountability shape security policy, with authentication factors such as something you know, have, or are, and the role of auditing and MFA.
Assess risk by combining probability of occurrence within a timeframe with the magnitude of financial impact, assign a conceptual score, and apply two risk assessment methodologies.
Quantitative risk assessment uses numerical values to quantify risk probability and impact, calculating asset value, annualized rate of occurrence, exposure factor, single loss expectancy, and annualized loss expectancy.
Differentiate four security control frameworks and understand how ISO 27,001 family, NIST risk management framework, SOC two, and PCI DSS guide information security management in cloud environments.
Understand disaster recovery metrics, including the recovery point objective (RPO) and recovery time objective (RTO), across four stages to minimize downtime and guide data restoration.
Learn to request a certificate from a certificate authority by choosing a type, submitting the CSR, completing validation, receiving the certificate, and installing it to establish trust.
Discover patterns across structured, semi-structured, and unstructured data using labeling, pattern matching, lexical analysis, and hashing to uncover trends. Enhances security and speeds decisions with actionable insights.
Explore how data loss prevention relies on data classification and labeling to identify sensitive information and enforce policies. Encrypting data in transit hides content from DLP, hindering exfiltration detection.
Track data events with robust auditability, chain of custody, and non-repudiation, leveraging SIEM for attribution, regulatory compliance, and secure incident investigations.
Learn how SIEM centralizes, normalizes, and correlates logs from multiple sources to detect anomalies, generate alerts, and support compliant, secure log management.
Demonstrates securing an AWS environment with GitHub actions in a production CI/CD pipeline, using an identity and access management user and GitHub environment secrets to deploy via S3 sync.
Explore quality assurance in software development, blending automated and manual testing across functional and non-functional types, including UAT, regression, static and dynamic testing, and supply chain risk management.
Explore the core principles of identity and access management, including identification, authentication, authorization, monitoring, and lifecycle management, to secure digital resources.
Learn how to perform a business impact analysis (BIA) that identifies critical resources, assigns asset values, and derives RTO, MTD, SLE, ALE, EF, and ARO through qualitative and quantitative methods.
In this lecture, we will discuss
the various rights and responsibilities involved in cloud computing
how those rights and responsibilities are apportioned between the cloud provider and the cloud customer
specific risks associated to each cloud platform and service, and
business continuity and disaster recovery strategies for use in the cloud.
This lecture addresses the data lifecycle within the cloud environment, as well as specific challenges in each phase.
We look at different data storage architectures that might be implemented in the cloud, and which service model might be best suited for each.
We discuss cryptography, including the importance and difficulty with key management, and the possibility of using homomorphic encryption in the future.
There are several use cases describing why we might want to obscure raw data and only display selected portions during operations.
We address Security Information and Event Management and DLP solutions in the cloud.
Clarify the split of responsibilities between cloud customers and providers across IaaS, PaaS, and SaaS, including data protection, governance, audits, SLAs, and risk management.
Explore ISO/IEC 27034-1 and the ONF/ANF frameworks to manage application security across the software lifecycle, guided by risk assessments and an application security management process.
Explore identity and access management, provisioning identities, password management, directory services, authentication and authorization, federation, and standards like SAML, OAuth, and OpenID Connect for cross-organizational SSO.
Examine the security mechanisms that power cloud applications, including API risks for REST and SOAP, and the role of encryption, cryptography, and tenancy separation in safeguarding data.
Investigate STRIDE threat modelling and QoS assurance to validate cloud applications. Compare vulnerability scanning, penetration testing, and both white-box and black-box approaches, with SAST and DAST.
Explore three approaches to threat modeling through application and infrastructure decomposition, data flow diagrams, process flow diagrams, and attack trees, to identify threats, prioritize countermeasures, and protect IT resources.
In this lecture, we will discuss
the use of redundancy in the design of cloud data centers
We will become aware of the Uptime Institute’s four tiers for describing and certifying the quality of data centers
We will discuss the concepts of training and awareness, and how training is related to due diligence efforts, and suggestions for properly utilising training to reduce the risk within your organisation, and finally,
we will describe basic application security methods, including threat modelling and software testing.
Compare US and EU privacy laws with reviews of Australia, Canada, Argentina, Switzerland, and APEC frameworks, and distinguish laws, regulations, and standards, including PCI DSS with its 12 requirements.
Define and implement a comprehensive security policy that integrates risk management, governance, due diligence, and compliance for outsourcing, contracts, and SLAs in global cloud environments.
"**Unlock Your CCSP Success: A Scenario-Focused Approach**
Dive into a revolutionary CCSP certification journey that goes beyond the ordinary. While other courses guide you through detailed content, we bring you a dynamic supplementary guide designed to elevate your understanding and fortify your knowledge.
Rather than just rehashing scripts, we've adopted an innovative approach. Our course revolves around scenario-focused quizzes, each unveiling critical concepts. We then craft in-depth tutorials around these scenarios, connecting the dots and illustrating the intricate relationships between different domains.
Say goodbye to a predictable domain-by-domain structure. In our quest to mirror the unpredictable nature of the exam, we've embraced randomness in our scenarios. Just like the real test, you won't know which domain your next question hails from.
But we don't stop there. Our course takes you beyond theoretical knowledge. By showcasing the practical application of security concepts using AWS services, we ensure you're not just prepared for the exam but primed to excel in real-world scenarios.
You may observe the presence of older content in our offerings. We are actively engaged in augmenting our repository with over 600 new scenarios, and over time, we will phase out the older content.
Thank you for embarking on this transformative journey with us. Your success is not just our goal; it's the destination.