StudyToCert

All certifications / CCSP / Cheat sheet

CCSP 2026 outline (effective Aug 1, 2026) cheat sheet

Every exam tip and key term from the free CCSP lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Cloud concepts, architecture & design (17%)

Exam tips

Key terms

Resource pooling
The provider serves many customers from shared physical resources that are dynamically assigned, with location largely hidden from the customer.
Rapid elasticity
The ability to scale capacity up or down quickly, often automatically, so it appears unlimited to the customer.
Cloud service broker
A partner that negotiates, integrates or aggregates cloud services from one or more providers on behalf of a customer.
Multitenancy
Several customers (tenants) sharing the same infrastructure while their data and workloads are kept logically separated.
IaaS
A service model in which the customer rents virtual compute, storage and networking and manages everything from the guest operating system up.
PaaS
A service model in which the provider runs the operating system and runtime, and the customer deploys and manages its own applications and data.
SaaS
A service model in which the provider delivers a complete application, and the customer manages users, configuration and data.
Cloud capability type
ISO/IEC 17788's classification of what a service offers the customer: infrastructure, platform or application capability.
Community cloud
A cloud shared by several organizations with common requirements, such as the same regulations, with shared governance and cost.
Hybrid cloud
Two or more distinct clouds, such as private and public, bound together so that data and applications can move between them.
Vendor lock-in
Dependence on one provider's proprietary services or formats that makes leaving costly or difficult.
Cloud bursting
Sending overflow workload from a private environment to public cloud capacity during demand peaks.
Shared responsibility model
The division of security duties between cloud provider and customer, which shifts according to the service model.
Security of the cloud
The provider's duties: facilities, hardware, host network and virtualization layer.
Security in the cloud
The customer's duties: data, identities, configuration and, depending on the model, operating systems and applications.
Accountability
Being answerable for the outcome; it stays with the data owner even when tasks are delegated to a provider.
Container
A lightweight package of an application and its dependencies that shares the host operating system kernel with other containers.
Serverless
A model in which the provider runs code on demand in response to events, and the customer manages no servers.
Trusted execution environment (TEE)
A hardware-isolated area of a processor where code and data are protected even from the host operating system and hypervisor.
Harvest now, decrypt later
The threat of attackers storing encrypted data today to decrypt it once quantum computers can break current public-key algorithms.
Large language model (LLM)
A machine learning model trained on large amounts of text that generates or analyzes language in response to prompts.
Prompt injection
An attack in which crafted input causes an AI model to ignore its instructions or perform unintended actions.
Data poisoning
Deliberately corrupting training data so that a model learns wrong or malicious behavior.
Shadow AI
Use of AI services by staff without the organization's approval or oversight.
Key management
The lifecycle of cryptographic keys: generation, distribution, storage, use, rotation, revocation and destruction.
Crypto-shredding
Making encrypted data unrecoverable by destroying all copies of the key that encrypted it.
Management plane
The console, APIs and tools used to create, configure and delete cloud resources.
Hypervisor
Software that creates and runs virtual machines and isolates them from one another.
Recovery time objective (RTO)
The maximum acceptable time to restore a service after a disruption.
Recovery point objective (RPO)
The maximum acceptable amount of data loss, measured as time before the disruption.
Business impact analysis (BIA)
An analysis that identifies critical business processes, the impact of losing them and the recovery objectives they need.
Security pattern
A proven, reusable design solution for a recurring security problem.
ISO/IEC 27017
A code of practice adding cloud-specific security controls and guidance for providers and customers.
CSA STAR
The Cloud Security Alliance's assurance program, with a self-assessment level and a third-party validated level, based on the Cloud Controls Matrix.
SOC 2 Type II
An auditor's report on the design and operating effectiveness of a service organization's controls over a period of time.
FIPS 140-3
The U.S. standard for validating cryptographic modules, with four increasing security levels.

Domain 2: Cloud data security (20%)

Exam tips

Key terms

Cloud data lifecycle
The six phases data passes through: create, store, use, share, archive and destroy.
Data dispersion
Splitting data into fragments stored in different locations so it can be rebuilt even if some fragments are lost.
Erasure coding
A method of adding calculated redundancy to data fragments so the original can be reconstructed from a subset of them.
Data flow diagram
A drawing of how data moves between systems, users and parties, showing trust boundaries and processing points.
Ephemeral storage
Temporary storage tied to an instance's life that is lost when the instance stops or is terminated.
Object storage
Storage that keeps data as objects with metadata in buckets, accessed through APIs rather than a file system.
Volume storage
Block storage presented to a virtual machine as a virtual disk that the guest formats with a file system.
Immutable backup
A backup copy that cannot be changed or deleted for a set period, protecting it from ransomware and mistakes.
Tokenization
Replacing a sensitive value with a random surrogate, with the mapping held in a separate secured vault.
Dynamic masking
Hiding or altering data values at query time based on the user's role, without changing the stored data.
Pseudonymization
Replacing identifiers with codes that can be re-linked to the person using additional information kept separately.
Salt
Random data added to a password before hashing so that identical passwords produce different hashes.
DLP
Tools and processes that discover sensitive data, monitor its use and movement, and enforce policies to prevent unauthorized disclosure.
Exact data matching
A DLP technique that detects specific records from a known sensitive dataset rather than generic patterns.
CASB
A cloud access security broker that sits between users and cloud services to give visibility and enforce security policy, including DLP.
Data in motion
Data travelling across a network, such as uploads, email and API calls.
HSM
A tamper-resistant hardware device that securely generates, stores and uses cryptographic keys.
Envelope encryption
Encrypting data with a data key and then encrypting that data key with a master key held in a key management service.
BYOK
Bring your own key: the customer generates keys in its own environment and imports them into the provider's key service.
HYOK
Hold your own key: keys stay in the customer's own key service outside the provider and are used remotely when needed.
Structured data
Data organized in a defined schema of rows and columns, such as a relational database table.
Semi-structured data
Data with tags or keys but no fixed schema, such as JSON, XML or log records.
Unstructured data
Data without a predefined model, such as documents, images, audio and free text.
Data residency
A requirement that data be stored, and sometimes processed, within a specific geographic location.
Data classification
Categorizing data by sensitivity, value and legal requirements to determine how it must be protected.
Data owner
The business role accountable for a data set, including deciding its classification and who may access it.
Data mapping
Documenting how data elements correspond between systems and where each category of data is stored and flows.
Data label
A visible or machine-readable marker that records a data item's classification.
IRM
Information rights management: encrypting content and attaching usage policies that are enforced wherever the file goes.
Persistent protection
Protection that stays with the data itself regardless of where it is stored or sent.
Dynamic policy control
The ability of the owner to change or revoke usage rights after the content has been distributed.
Automatic expiration
An IRM feature that stops protected content from being opened after a set date or period.
Retention period
The length of time a category of data must be kept to meet legal, regulatory, contractual or business requirements.
Legal hold
An instruction to preserve data relevant to anticipated or actual litigation, overriding normal deletion.
Storage limitation
The privacy principle that personal data should be kept no longer than necessary for its purpose.
Archiving
Moving inactive data to long-term storage where it stays protected and retrievable for its retention period.
Auditability
The ability to review a complete, reliable record of events to verify what happened.
Traceability
The ability to follow an action or data item through systems back to its origin and actor.
Non-repudiation
Assurance that someone cannot credibly deny having performed an action.
Identity attribution
Linking each logged action to a specific, unique person or service identity.
Data provenance
A record of where data came from and how it has been changed, used to establish trust in it.
Backdoor (in ML)
Hidden behavior planted in a model through poisoned training data that activates on a specific trigger.
Membership inference
An attack that determines whether a particular record was part of a model's training data.
Indirect prompt injection
Malicious instructions hidden in content, such as a web page or document, that an AI system reads and follows.

Domain 3: Cloud platform & infrastructure security (17%)

Exam tips

Key terms

Availability zone
One or more physically separate data centers within a region, with independent power, cooling and networking.
Software-defined networking (SDN)
Networking in which a software controller manages traffic decisions separately from the hardware that forwards packets.
Control plane vs data plane
The control plane decides how traffic or resources are managed; the data plane carries out the actual forwarding or processing.
Region
A geographic area containing multiple availability zones operated by a cloud provider.
Concurrently maintainable
Tier III property: any component can be removed for planned maintenance without shutting down IT equipment.
Fault tolerant
Tier IV property: the facility continues operating through any single unplanned component failure.
Mantrap
An entry area with two interlocking doors that allows only one authenticated person through at a time.
Hot aisle/cold aisle containment
Arranging server racks so cool intake air and hot exhaust air are kept separate, improving cooling efficiency.
VM escape
An attack in which code running inside a virtual machine breaks out to interact with the hypervisor, host or other VMs.
VM sprawl
Uncontrolled growth of virtual machines, leaving unmanaged, unpatched systems running.
Side-channel attack
An attack that infers secret data from physical effects such as timing, cache behavior or power use rather than from a direct flaw.
Cloud security posture management (CSPM)
Tools that continuously check cloud configurations against policies and best practices and report or fix deviations.
Security control
A safeguard or countermeasure that avoids, detects, counteracts or reduces a security risk.
Defense in depth
Using multiple independent layers of controls so that failure of one does not expose the asset.
Workload identity
An identity assigned to an application or service so it can authenticate without stored static credentials.
Phishing-resistant MFA
Authentication, such as FIDO2 security keys or passkeys, that cannot be captured and replayed by a fake login page.
Type 1 hypervisor
A bare-metal hypervisor that runs directly on hardware, used by cloud providers for its small attack surface.
Type 2 hypervisor
A hosted hypervisor that runs as an application on a general-purpose operating system.
Break-glass account
An emergency administrative account kept locked away and used only when normal access fails, with every use alerted and reviewed.
Just-in-time access
Granting elevated privileges only when needed and for a limited time, rather than permanently.
Security group
A stateful virtual firewall attached to an instance or interface that allows specified traffic and automatically permits responses.
Network ACL
A usually stateless subnet-level filter with ordered allow and deny rules for inbound and outbound traffic.
Microsegmentation
Fine-grained network policy that restricts communication between individual workloads to only what is required.
Zero trust
A security model that grants access based on continuous verification of identity and context rather than network location.
Maximum tolerable downtime (MTD)
The longest a business process can be unavailable before the organization suffers unacceptable harm.
Pilot light
A DR strategy in which core data is replicated and minimal infrastructure is kept ready to scale up during a disaster.
Warm standby
A DR strategy in which a scaled-down but functional copy of the environment runs continuously and can be scaled up quickly.
Tabletop exercise
A discussion-based test in which participants walk through a scenario and their roles without touching systems.
SIEM
Security information and event management: a platform that collects, normalizes, correlates and alerts on logs from many sources.
Flow log
A record of network connections showing metadata such as source, destination, ports, protocol and bytes, without packet payloads.
Traffic mirroring
A cloud feature that copies network packets from a customer's instance interfaces to a monitoring or analysis destination.
Correlation
Linking related events from multiple sources to detect patterns that single events do not reveal.

Domain 4: Cloud application security (16%)

Exam tips

Key terms

Security champion
A developer or engineer embedded in a team who receives extra security training and promotes secure practices.
Hard-coded secret
A password, key or token written directly into source code, configuration or images.
Insecure default
A setting that is unsafe out of the box and must be changed to be secure.
Microservices
An architecture that splits an application into small, independently deployed services communicating over APIs.
STRIDE
A threat classification: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
DREAD
A threat scoring model: damage, reproducibility, exploitability, affected users and discoverability.
PASTA
Process for Attack Simulation and Threat Analysis, a seven-stage risk-centric threat modeling method.
Abuse case
A description of how an attacker might misuse a feature, written alongside normal use cases to drive security requirements.
OWASP Top 10
A regularly updated awareness list of the most critical web application security risk categories.
CWE Top 25
MITRE's ranked list of the most dangerous specific software weaknesses based on real vulnerability data.
Server-side request forgery (SSRF)
A flaw that lets an attacker make a server send requests to destinations of the attacker's choosing, often internal services.
Broken access control
A failure to enforce what authenticated users are allowed to do, letting them act outside their permissions.
ASVS
The OWASP Application Security Verification Standard, a list of testable security requirements organized into three verification levels.
Parameterized query
A database query where user input is passed as separate parameters, so it can never be executed as code.
Software configuration management
The discipline of tracking and controlling changes to code, dependencies, build and deployment configuration.
Output encoding
Transforming data before display so that the browser treats it as text rather than executable code.
SAST
Static application security testing: analyzing code without executing it to find security flaws.
DAST
Dynamic application security testing: probing a running application from the outside to find exploitable weaknesses.
IAST
Interactive application security testing: an agent inside the running application observes behavior during tests and reports flaws with code context.
SCA
Software composition analysis: identifying third-party components and their known vulnerabilities and licenses.
Software supply chain
All the components, tools, processes and suppliers involved in building and delivering software.
Dependency confusion
An attack where a malicious public package with the same name as an internal one is pulled into a build instead of the real package.
Artifact signing
Digitally signing build outputs so consumers can verify they came from the expected source and were not altered.
Approved API
An external or internal interface that has been security-reviewed and authorized for use by the organization.
WAF
A web application firewall that filters HTTP traffic at layer 7 to block attacks such as injection and cross-site scripting.
API gateway
A service that fronts APIs to handle authentication, authorization, rate limiting, routing and logging.
Database activity monitoring (DAM)
Monitoring database queries and activity in real time to detect and alert on suspicious or policy-violating access.
Sandbox
An isolated, restricted execution environment that contains the effects of untrusted code.
Identity provider (IdP)
The system that authenticates users and issues assertions or tokens that other applications trust.
SAML 2.0
An XML-based standard for exchanging authentication and attribute assertions between an identity provider and a service provider.
OpenID Connect
An identity layer on top of OAuth 2.0 that provides authentication using JSON web tokens.
CASB
A cloud access security broker that gives visibility and policy enforcement between users and cloud services.

Domain 5: Cloud security operations (17%)

Exam tips

Key terms

Trusted platform module (TPM)
A hardware chip that securely stores keys and boot measurements, supporting secure and measured boot and disk encryption.
Golden image
A hardened, pre-approved template used to build consistent, secure instances.
Measured boot
Recording measurements of each boot component in the TPM so that the system's startup integrity can be verified.
Baseboard management controller
An out-of-band management processor on a server that allows remote control even when the operating system is off.
Bastion host
A hardened server that is the only allowed entry point for administrative access to systems in a private network.
DNSSEC
DNS Security Extensions, which sign DNS records so resolvers can verify their authenticity and integrity.
VLAN
A virtual LAN that logically separates traffic on a shared physical network.
Privileged access management (PAM)
Tools and processes that control, broker, record and audit use of privileged accounts.
Hardening
Reducing a system's attack surface by removing unnecessary functions and applying secure configuration settings.
Infrastructure as code (IaC)
Defining and deploying infrastructure through machine-readable template files kept in version control.
Configuration drift
Differences that develop between a system's actual configuration and its approved baseline or code definition.
Immutable infrastructure
An approach in which servers are never changed after deployment; updates are made by replacing them with new instances.
High availability (HA)
Design that keeps a service running despite component failure, for example by restarting VMs on other hosts in a cluster.
Maintenance mode
A host state in which workloads are moved elsewhere so the host can be patched or repaired without downtime.
Service quota
A provider-imposed limit on the number or size of resources an account can use.
3-2-1 backup rule
Keep three copies of data on two different media or services, with one copy off-site or isolated.
Change management
The process that ensures changes are assessed, approved, tested, implemented and reviewed in a controlled way.
Problem management
The process of finding and eliminating the root causes of incidents to prevent recurrence.
CMDB
Configuration management database: a repository of configuration items and the relationships between them.
ISO/IEC 20000-1
The international standard specifying requirements for an IT service management system.
Chain of custody
The documented, unbroken record of who collected, handled, transferred and stored each piece of evidence.
Order of volatility
The principle of collecting the most short-lived evidence, such as memory, before more persistent evidence such as disk.
ISO/IEC 27037
The international guideline for identifying, collecting, acquiring and preserving digital evidence.
Forensic image
An exact, verified bit-for-bit copy of storage media, used for analysis in place of the original.
Stakeholder
Any person or organization affected by, or with an interest in, a service or incident.
Breach notification
A legally or contractually required notice to regulators or affected individuals after certain data breaches.
Status page
A provider's public page reporting current service health, incidents and maintenance.
Communication plan
A documented plan stating who communicates what to which stakeholders, when and through which channels.
SOC
Security operations center: the team and capability that continuously monitors, detects, investigates and coordinates response to security events.
SOAR
Security orchestration, automation and response: tools that automate and coordinate incident response steps through playbooks.
Alert fatigue
Desensitization caused by too many alerts, especially false positives, leading analysts to miss real threats.
Authenticated scan
A vulnerability scan that logs in to systems to inspect installed software and configuration in detail.
Anomaly detection
Identifying events that deviate significantly from a learned baseline of normal behavior.
UEBA
User and entity behavior analytics: analysis of the behavior of users, devices and service accounts to detect threats.
False negative
A real malicious event that a detection system fails to flag.
Human in the loop
A design in which a person reviews or approves decisions before an automated system acts on them.

Domain 6: Legal, risk & compliance (13%)

Exam tips

Key terms

Jurisdiction
The legal authority of a court or government over people, organizations and data within a territory.
eDiscovery
The identification, preservation, collection, review and production of electronically stored information for legal matters.
ISO/IEC 27050
The international standard series providing guidance on electronic discovery.
Data localization
A legal requirement that certain data be stored or processed within a specific country.
Data controller
The party that determines the purposes and means of processing personal data and is accountable for it.
Data processor
A party that processes personal data on behalf of the controller, such as a cloud provider.
Business associate agreement (BAA)
A HIPAA-required contract under which a service provider agrees to protect PHI it handles for a covered entity.
Privacy impact assessment (PIA)
An assessment of how a project collects, uses and protects personal data and what privacy risks it creates.
Right to audit
A contract clause allowing the customer, or its auditor, to audit the provider's controls.
SOC 3
A general-use summary report on a service organization's controls against the trust services criteria, without detailed test results.
Complementary user entity controls (CUECs)
Controls a customer must implement for the provider's controls described in a SOC report to be effective.
Gap analysis
A comparison of current controls with a target standard to identify what is missing or inadequate.
Enterprise risk management (ERM)
An organization-wide approach to identifying, assessing and treating risks in line with business objectives.
Risk appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
Residual risk
The risk that remains after controls and other treatments have been applied.
Risk transfer
Shifting the financial consequences of a risk to another party, for example through insurance or contract terms.
ISO/IEC 31000
An international standard giving principles and guidelines for risk management applicable to any organization.
NIST Risk Management Framework
The seven-step lifecycle in NIST SP 800-37: prepare, categorize, select, implement, assess, authorize and monitor.
Key risk indicator (KRI)
A metric that signals increasing exposure to a risk, used as an early warning.
ENISA cloud risk assessment
ENISA's analysis of cloud-specific risks across policy and organizational, technical and legal categories.
Service level agreement (SLA)
A contract component defining measurable service commitments and remedies if they are not met.
Master services agreement (MSA)
The overarching contract setting the legal terms that govern all work between the parties.
Statement of work (SOW)
A document describing specific services, deliverables, schedule and costs under the MSA.
ISO/IEC 27036
The international standard series on information security in supplier relationships, including cloud services.
Organizational policy
A high-level, management-approved statement of intent that applies across the whole organization.
Functional policy
A policy governing a specific security area, such as access control or incident response.
Guardrail
An automated organization-wide control that prevents or detects actions that violate policy in cloud accounts.
Policy exception
A documented, approved and time-limited deviation from a policy, with the associated risk accepted by the right authority.
EU AI Act
The European Union's risk-based regulation of artificial intelligence systems, with obligations that increase with risk.
Algorithmic bias
Systematic and unfair differences in an AI system's outcomes for particular groups of people.
Explainability
The ability to describe in understandable terms how an AI system reached a particular output or decision.
ISO/IEC 42001
An international standard specifying requirements for an AI management system.
PCI DSS
The Payment Card Industry Data Security Standard, which sets security requirements for entities handling cardholder data.
FedRAMP
The US government program that standardizes security assessment, authorization and continuous monitoring of cloud services for federal use.
NERC CIP
North American Electric Reliability Corporation Critical Infrastructure Protection standards for the bulk electric system.
Responsibility matrix
A provider document mapping each compliance requirement to the provider, the customer or both.
Study CCSP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CCSP study plan