
Explore the 2019 official CCSP exam outline, overview of the six domains, and practical exam strategies, including pacing, question format, and cloud provider vs customer perspectives.
Explore cloud computing concepts and roles, including provider, customer, partner, broker, and carrier, and identify essential characteristics like on-demand self-service, broad network access, multitenant, rapid elasticity, and resource pooling.
Describe cloud reference architecture, including IaaS, PaaS, SaaS, and deployment models like public, private, community, and hybrid. Highlight shared responsibilities, interoperability, portability, security, availability, governance, and regulatory considerations.
Explore security concepts relevant to cloud computing, including cryptography, key management, access control, and data sanitization, with a deep dive into symmetric and asymmetric crypto and session keys.
Understand design principles of secure cloud computing, including cloud data lifecycle and disaster recovery. Evaluate cost-benefit, portability, interoperability, and vendor lock-in across SASE, IHS, and Pass.
Assess cloud service providers by verifying criteria, considering potential criteria and systems subsystem product certifications; rely on third-party external auditor reports to demonstrate due diligence for stakeholders.
Explore domain one in WannaBeA CCSP with review questions spanning private cloud governance, authentication, encryption for live video chats, key management, and measured service.
Describe cloud data concepts, including the data lifecycle with create, store, use, share, archive, and destroy phases, and how data dispersion via chunks and erasure coding enhances security and resilience.
Design and implement cloud storage architectures, including object, file, and block storage with ephemeral and long-term options, and use content delivery networks to optimize proximity and service quality.
Design and apply data security technologies and strategies, including encryption and key management, hashing, masking, and tokenization, with data loss prevention and anonymization to protect sensitive information.
Differentiate structured data designed for querying from unstructured data lacking fixed locations, then implement discovery with metadata, labels, and automation using content and context analytics to assess regulated data.
Learn to implement data classification by mapping data across stores, labeling sensitive data such as pii and ephi, and enforcing audit-ready controls to protect regulatory information under hipaa and gdpr.
Design and implement information rights management (irm) to protect data with file-based access controls, where protection follows the file, centralized provisioning, time-based access, certificates, and platform-agnostic protections across devices.
Define governance-driven data retention and archiving policies, and implement secure deletion, backups, and cryptographic erasure in cloud environments to minimize risk and comply with legal holds.
Explore how to design auditability, traceability, and accountability for data events, define event sources, implement secure, centralized log storage and analysis, and ensure chain of custody and non-repudiation.
Explore domain 2 review topics on hashing for integrity, digital signatures, and encryption. Identify IT environment events, data retention baselines, anonymization, and log data security.
Explore cloud infrastructure components from the provider perspective, including physical data centers, compute, storage, virtualization, management plane, and essential access controls like firewalls and identity and access management.
Design a secure data center with tenant partitioning, memory isolation, application isolation, and access controls; select a location considering disasters, climate, and buy-or-build options, plus robust hvac and multi-vendor connectivity.
Assess cloud infrastructure risks through qualitative and quantitative risk assessment and analysis, explore cloud vulnerabilities and threats, and apply defense in depth with layered controls and continuous monitoring.
Design and plan security controls across cloud and on-premise environments, including man traps, turnstiles, physical protection, and audit mechanisms.
Plan and test disaster recovery and business continuity to protect data and operations, defining RTO, RPO, MTD, and cloud and traditional data center strategies.
Explore domain 3 review questions on recovery point objective and recovery time objective, cloud risks like tenant-to-tenant breaches, and virtualization security concepts such as guest escape and turnstile.
Advocate training and awareness for cloud application security, covering cloud development basics, common vulnerabilities, porting challenges, and the OWASP top 10 risks for exam readiness.
Describe the secure software development lifecycle—from requirements definition to maintenance—highlighting functional and non-functional requirements, ongoing security monitoring, and methodologies such as waterfall, spiral, agile, DevSecOps, and CI/CD.
Apply the secure software development lifecycle from start to finish, address cloud risks, conduct threat modeling with the Stryde model, and enforce automated configuration management for quality assurance.
Apply cloud software assurance and validation by practicing functional testing and security testing methodologies, including use case, misuse case, and fuzz testing, as well as static and dynamic security testing.
Apply verified, secure software and approved APIs, and manage supply chain risks for third-party software. Leverage open source validation and clear contracts and SLAs to ensure secure acquisition.
Explore cloud application architecture and security components, including web application firewalls, database activity monitoring, API gateways, XML firewalls, sandboxing, and application virtualization for modular microservices in the cloud.
Explore how to design identity and access management solutions with federated identity, identity providers, single sign-on, multi-factor authentication, and CASB for cloud security, including Open ID, Oath, and Samuel standards.
Explore domain 4 review questions on data security foundations, authentication versus encryption, key management services, single sign-on benefits, virtualization and orchestration advantages, and user-involved testing methods.
Implement and secure the physical and logical cloud infrastructure by securing bios and tpm, hardening virtualization tools and storage and network controllers, enforcing strict admin controls and secure baselines.
Operate physical and logical cloud infrastructure by enforcing strict local and remote access, securing KVM and RDP, and applying secure network configurations (DNS, DHCP, VLAN, VPN) with hardened OS baselines.
Implement formal change management to enforce operational controls and standards, guiding IT environment changes through request, review, approval, testing, implementation, maintenance, and disposal, with thorough documentation at every phase.
Explore forensic data collection and evidence management, emphasizing chain of custody, authenticity, completeness, reliability, and admissibility. Learn to acquire and preserve digital evidence from networks and endpoints with integrity.
Coordinate communication with vendors, customers, partners, regulators, and stakeholders by maintaining centralized contact data, testing it regularly, and delivering tailored, single voice messages during incidents.
Learn to run security operations with a centralized SoC, monitor controls, capture and analyze logs with SIEM, and manage incidents from detection to lessons learned.
Explore domain five review by examining incident reporting recipients, evidence types, change management roles, senior management decisions on incident response, and honeypot concepts.
Articulate the legal requirements and unique risks in cloud environments, including multi-tenancy, cross-jurisdictional laws, and potential data seizures. Manage liability, regulatory frameworks, and eDiscovery challenges with providers.
Understand privacy issues, including contractual versus regulated private data, PII and HIPA-protected information, and GDPR concepts like data minimization, storage, cross-border limits, and the right to be forgotten.
Explore cloud audit methodologies, including SoC reports and scoping, tailoring, and gap analysis for internal and external audits, ensuring compliant, risk-aware cloud governance.
Assess cloud implications for enterprise risk management by evaluating providers' risk programs and the data owner controller versus custodian processor roles, plus rmf controls (800-37, 800-53) and kpis and kris.
Explore outsourcing and cloud contract design, focusing on service level agreements, vendor management, statements of work, metrics, audits, termination terms, data access, and compliance to safeguard cloud customer value.
Review domain six questions on privacy law conformity, vulnerability identification through penetration testing, cloud SLA metrics, and risk acceptance, highlighting external audits as independent reviews.
An explanation of the material found in the ISC2 CCSP 2019 Exam Outline, with particular focus on what you might expect to see on the exam. If you've been considering taking the CCSP test, this is the course for you. The course offers more than seven hours of video content at a highly-competitive price. Drawn from the instructor's own experience as an official ISC2 CCSP instructor, the course is delivered in a simple, straightforward manner, designed to help you pass the exam.
Students are encouraged to review the ISC2 CCSP Exam Outline, available for free from the ISC2 website. The course includes other recommendations and suggestions for study purposes, as well as guidance on how to approach the test, and which topics are most likely to appear. This course is not a substitute for the requisite experience-- the course content does not teach many of the basics necessary for attaining certification; students are expected to have a background in IT prior to this course. At least five years of specific experience is necessary to qualify for the certification; students should have that much knowledge, as a minimum, prior to taking this course.
WannaBeA. Success and certification are only a class away.