Cloud Security

Please note the knowledge domains and topics outlined here are for guidance only and subject to change.

Review MDM configuration policies

–

Understand the purpose MDM solutions and the functionality they offer

Understand the difference between roles and policies

–

Identify and understand the key administrative roles in AWS

Understand the difference between AD, Azure AD DS and Azure AD

–

Understand and review conditional access policies

–

Identify and understand the key administrative roles in Azure

Understand the different security responsibility boundaries between IaaS, PaaS and SaaS

–

Understand the differences between cloud and on-prem architecture. Understand how to link between the two

Understands how (Distributed) Denial of Service attacks are performed and the protective measures available in cloud environments

–

Understands the financial implications of excessive resource consumption

Can analyse logging configuration within a cloud environment and advise on improvements

–

Can analyse the configuration of resource monitoring and alarm generation and advise on improvements

Can analyse logging configuration within a cloud environment and advise on improvements

–

Can analyse the configuration of resource monitoring and alarm generation and advise on improvements

Understands the concepts of a VPC and the implications on performing security assessments

–

Can competently assess resources within a private cloud-hosted environment, advising on any necessary temporary changes that may be needed (e.g. creation of bastion hosts, changes to Security Groups / firewalls)

Understands common pitfalls associated with the design and implementation of application authorisation mechanisms