← All CCSK Flashcard Decks

Identity and Access Management in Cloud Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Identity and Access Management in Cloud flashcards as text
  1. What is 'zero trust' architecture and why does CCSK align with its principles for cloud security?

    Answer: A security model that requires continuous verification of all users and devices regardless of network location

    Zero trust eliminates implicit trust based on network location, requiring continuous authentication and authorization for every access request.

  2. According to CCSK, what is the risk of 'credential stuffing' attacks against cloud management APIs?

    Answer: Attackers use stolen credential lists to gain unauthorized access to cloud accounts and resources

    Credential stuffing automates login attempts using breached usernames and passwords, targeting cloud management APIs to gain access to infrastructure.

  3. What is 'identity governance and administration' (IGA) and why is it important in cloud environments?

    Answer: A set of processes and tools for managing the identity lifecycle including provisioning, certification, and de-provisioning

    IGA manages the full lifecycle of identities — creating, reviewing, certifying, and removing access — ensuring governance across complex cloud environments.

  4. What does CCSK say about using shared accounts or credentials in cloud environments?

    Answer: Shared accounts should be avoided because they prevent individual accountability and complicate incident investigation

    Shared credentials eliminate individual accountability, making it impossible to attribute actions to specific users during security investigations.

  5. What is 'continuous access evaluation' (CAE) and how does it improve cloud security?

    Answer: Re-evaluating user access tokens in near-real-time based on risk signals rather than waiting for token expiry

    CAE enables cloud systems to revoke or challenge access tokens immediately when risk signals appear (e.g., location change, account compromise), rather than waiting for token expiry.

  6. In the CCSK framework, what distinguishes authentication from authorization in cloud IAM?

    Answer: Authentication verifies identity (who you are); authorization determines what actions you are permitted to perform

    Authentication confirms the identity of a user or system, while authorization determines what resources and actions that verified identity is allowed to access.