CCSP · Domain 5
Cloud Security Operations
About 16% of the exam
Build the physical and logical environment
- Hardware baseline: BIOS, firmware, TPM
- Secure boot and measured boot
- Hypervisor hardened, management isolated
- Storage controllers and encryption configured
- Virtualization toolsets patched and restricted
- Network: VLANs, TLS, DNSSEC, IPsec
- Provider builds it, customer verifies it
Operate and harden
- Baselines from CIS benchmarks or vendor guides
- Remove unneeded services and ports
- Host-based firewalls and IDS on guests
- Patch on schedule, emergency path defined
- Log everything to a central collector
- Backup and restore tested for guests
- Time synchronization on UTC
- Performance and capacity monitored
Operational management processes
Control the change
- Change management
- approve, test, schedule, record
- Configuration management
- baseline, CMDB, drift detection
- Release and deployment
- controlled path to production
- Patch management
- assess, test, deploy, verify
Keep it running
- Incident management
- restore service fast
- Problem management
- find and remove root cause
- Availability management
- meet the uptime target
- Capacity management
- enough resources, not too many
- Continuity management
- survive the disaster
- Service level management
- define, measure, report SLAs
Incident restores service; problem removes the cause; change controls what touches production
Logging and SIEM
- Aggregate logs from every source centrally
- Provider audit trails show all API calls
- Flow logs, DNS logs, storage access logs
- Correlate identity events with data events
- Protect log integrity, restrict who deletes
- Retention set by the strictest regulation
- UTC everywhere for correlation
- Tune to reduce alert fatigue
Incident response in cloud
- Prepare
- Detect and analyze
- Contain
- Eradicate
- Recover
- Lessons learned
- Isolate first, then investigate
- Rotate compromised credentials immediately
- Snapshot before remediation
- Provider cooperation defined in contract
- Immutable infra: replace to recover
Forensics in the cloud
- Chain of custody from first snapshot
- Hash images, work on copies
- Order of volatility: memory before disk
- Multitenancy limits physical access
- Provider logs need contractual access
- Jurisdiction decides what you may seize
- eDiscovery: identify, preserve, collect, produce
- Time zones and clock skew break timelines
You cannot seize a shared disk; collect logical evidence and prove its integrity
SOC practice and metrics
- MTTD
- mean time to detect
- MTTR
- mean time to respond or recover
- Threat hunting
- proactive, hypothesis driven search
- UEBA
- behavior baselines for users, entities
- SOAR
- orchestrate and automate response
- MDR
- managed detection with active response
- MSSP
- monitoring and alerting, less response
- Maturity signal
- incidents found by hunting
Vulnerability and patch management
- Authenticated scans on schedule
- Agentless discovery for ephemeral assets
- Prioritize by exploitability and exposure
- Test patches, then stage, then production
- Rebuild images rather than patch instances
- Track exceptions with expiry dates
- Verify remediation with a rescan
Configuration and drift
- Approved baseline for every asset type
- Continuous compliance scanning against it
- Auto-remediate drift where safe
- Every change through the pipeline
- Dynamic inventory for auto-scaling fleets
- Tag resources for owner and classification
- Configuration is the top cloud breach cause
Network security operations
Controls
- Firewalls, security groups, WAF
- IDS detects, IPS blocks inline
- Honeypots and deception for early warning
- Bastion hosts or zero-trust access brokers
- DDoS protection at the edge
- Network flow analysis for lateral movement
Detection signals
- Odd-hour outbound transfers: exfiltration
- Many accounts, one password: spraying
- Long, high-entropy DNS: tunneling
- Known bad destinations: command and control
- New geographies on storage buckets
- Privilege escalation in orchestrator logs
Communicating with stakeholders
- Vendors: SLAs, support escalation, notices
- Customers: incident notices, status pages
- Partners: interconnection agreements, shared risk
- Regulators: breach notice on legal clock
- Internal: agreed cadence, one voice
- Legal reviews external statements
- Never speculate on cause or scope
Security in automated operations
- Security testing built into CI/CD
- Event-driven remediation with rules engines
- Runtime monitoring agents on every node
- Redundant monitoring across regions
- Automate the response, keep human approval for destructive steps
- Limit pipeline identities to least privilege
- Measure automation with MTTR
Rapid recall: the FIRST move
- Talking to C2
- isolate from the network
- Service account exposed
- disable or rotate credentials
- Odd 3 AM transfer
- review flow and database logs
- Bucket read abroad
- check permissions and ACLs
- Compromised VM
- snapshot disk and memory
- Rate limits block logs
- ask provider for temporary increase
- Alert flood
- correlate and prioritize automatically
Reference strip: processes, logs, response, terms
Management processes
- Change, configuration, release
- Incident, problem, availability
- Capacity, continuity, service level
Log sources
- Provider API audit trail
- Flow logs, DNS, storage access
- Identity provider sign-ins
- Orchestrator and container runtime
Response order
- Prepare, detect, contain
- Eradicate, recover, learn
- Snapshot before you fix
Forensics words
- Chain of custody, hash, image
- Order of volatility
- eDiscovery, legal hold
- Jurisdiction, provider cooperation
Operations acronyms
- SIEM, SOAR, UEBA, EDR
- MTTD, MTTR, SLA
- MDR, MSSP, SOC
- CIS benchmark, CMDB, drift
Quick exam traps
- Trap: Problem management restores service as fast as possible
- Trap: Cloud forensics can seize the physical disk like on-premises
- Trap: Nightly automated scans remove the need for human review
- Trap: MSSP and MDR are the same service
- Trap: Patch a compromised instance and leave it in production
- Trap: Each region should log in its own local time
- Trap: Alert volume is a measure of SOC effectiveness
- Trap: The provider handles incident response for your workloads
cybercertprep.com · original revision sheet written from the public body of knowledge