Cloud security controls, identity management, and compliance concepts tested on the CompTIA Cloud+ exam.
36 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the principle of least privilege?
- Users and processes should have only the minimum permissions needed to perform their job functions.
- What is role-based access control (RBAC)?
- A method of controlling access to resources based on user role assignments rather than individual permissions.
- What is multi-factor authentication (MFA)?
- Authentication requiring multiple verification methods, such as password plus a one-time code.
- What does AAA stand for in security?
- Authentication, Authorization, and Accounting.
- What is encryption at rest?
- The encryption of data while it is stored on disk or in databases.
- What is encryption in transit?
- The encryption of data while it is being transmitted over networks.
- What is a cryptographic hash?
- A one-way function that takes input and produces a fixed-length output that cannot be reversed.
- What is symmetric encryption?
- Encryption using the same key for both encryption and decryption.
- What is asymmetric encryption?
- Encryption using two keys: a public key for encryption and a private key for decryption.
- What is a digital certificate?
- A document that verifies the ownership of a public key, typically signed by a certificate authority.
- What does PKI stand for?
- Public Key Infrastructure.
- What is compliance?
- The process of meeting legal, regulatory, and organizational requirements.
- What is HIPAA?
- Health Insurance Portability and Accountability Act, a US regulation protecting health information privacy.
- What is PCI DSS?
- Payment Card Industry Data Security Standard, a set of requirements for handling payment card data.
- What is SOC 2?
- Service Organization Control 2, a framework for evaluating security, availability, processing integrity, confidentiality, and privacy.