CSA - Firebrand's training for CSA's Certified Cloud Security Knowledge (CCSK) exam

Dauer

Dauer:

Nur 2 Tage

Methode

Methode:

Klassenraum / Online / Hybrid

nächster Termin

nächster Termin:

28.9.2020 (Montag)

Overview

On this 2-day accelerated Firebrand course for CSA's Certificate of Cloud Security Knowledge (CCSK) exam, you'll validate your understanding of the best practices surrounding cloud security. This Firebrand course, designed to deliver knowledge equivalent to the CSA's CCSK Basic and the CCSK Plus, aims to ensure that you have a demonstrated awareness of the security threats facing your cloud infrastructure.

On this Firebrand course you'll cover:

  • A comprehensive review of cloud security fundamentals
  • The major domains in the latest Guidance document from Cloud Security Alliance (CSA)
  • Recommendations from the European Network and Information Security Agency (ENISA)
  • Expanded material and hands-on tasks in a series of exercises that include bringing a fictional organisation securely into the cloud.

Firebrand's unique Lecture | Lab | Review technique combines both theoretical knowledge with practical, hands-on skills. This technique will accelerate your learning and ensure you have the ability to apply your new found knowledge as soon as you return to work.

As part of Firebrand' own course, you'll be prepared for and sit the CSA Certificate of Cloud Security Knowledge (CCSK) exam. This is covered by your Certification Guarantee.

This course is aimed at a broad range of professionals with responsibilities related to cloud computing and security.

Vier Gründe, warum Sie Ihren CCSK Kurs bei Firebrand Training machen sollten:

  1. Zwei Optionen für Ihr Training. Wählen Sie für Ihren CCSK Kurs zwischen einem Präsenztraining oder der onlinebasierten Variante
  2. Unser CCSK Kurs umfasst ein Alles-Inklusive-Paket. Damit Sie sich ganz auf das Lernen konzentrieren können.
  3. Lernen Sie mit einem mehrfach ausgezeichneten Trainingsanbieter. Bereits 76194 Teilnehmer haben unsere bewährten Firebrand-Intensiv-Trainings mit Erfolg besucht.
  4. Bestehen Sie Ihre CCSK Prüfung auf Anhieb. Unsere praxiserfahrenen Trainer verwenden den "Lecture-Lab-Review"-Ansatz, damit Sie den bestmöglichen Trainingserfolg erzielen.

Benefits

In einem Firebrand Intensiv-Training profitieren Sie von folgenden Vorteilen:

  • Zwei Optionen - Präsenz- oder Onlinetraining
  • Ablenkungsfreie Lernumgebung
  • Eigene Trainings- und Prüfungszentren (Pearson VUE Select Partner)
  • Effektives Training mit praktischen Übungseinheiten und intensiver Betreuung durch unsere Trainer
  • Umfassendes Leistungspaket mit allem, was Sie benötigen, um Ihre Zertifizierung zu erhalten, inklusive unserer Firebrand Leistungsgarantie.

Curriculum

On this Firebrand Course, you'll cover the following topics:

Domain 1: Cloud Computing Concepts and Architectures

  • Defining Cloud Computing
  • Definitional Model
    • Essential Characteristics
    • Service Models
    • Deployment Models
  • Reference and Architecture Models
    • Infrastructure as a Service
    • Platform as a Service
    • Software as a Service
  • Logical Model
  • Cloud Security and Compliance Scope and Responsibilities
  • Cloud Security Models
    • A Simple Cloud Security Process Model
  • Governing in the Cloud
  • Operating in the Cloud

Domain 2: Governance and Enterprise Risk Management

  • Governance
    • Tools of Cloud Governance
  • Enterprise Risk Management
  • The Effects of Service Model and Deployment Model
    • Service Models
    • Deployment Models
    • Cloud Risk Management Trade-Offs
    • Cloud Risk Management Tools

Domain 3: Legal Issues, Contracts and Electronic Discover

  • Legal Frameworks Governing Data Protection and Privacy
    • Common Themes
    • Required Security Measures
    • Restrictions to Cross-border Data Transfers
    • Regional Examples – GDPR, NIS Directive, US Federal and State Laws
  • Contracts and Provider Selection
    • Internal Due Diligence
    • Monitoring, Testing, and Updating
    • External Due Diligence
    • Contract Negotiations
    • Reliance on Third-Party Audits and Attestations
  • Electronic Discovery
    • Possession, Custody and Control
    • Relevant Cloud Applications and Environment
    • Searchability and E-Discovery Tools
    • Preservation
    • Data Retention Laws and Record Keeping Obligations
    • Collection
    • Direct Access
    • Native Production
    • Authentication
    • Cooperation Between Provider and Client in E-Discovery
    • Response to a Subpoena or Search Warrant
    • More Information

Domain 4: Compliance and Audit Management

  • Compliance
    • How Cloud Changes Compliance
  • Audit Management
    • How Cloud Changes Audit Management

Domain 5: Information Governance

  • Cloud Information Governance Domains
  • The Data Security Lifecycle
    • Locations and Entitlements
    • Functions, Actors, and Controls

Domain 6: Management Plane and Business Continuity

  • Business Continuity and Disaster Recovery in the Cloud
    • Architect for Failure
  • Management Plane Security
    • Accessing the Management Plane
    • Securing the Management Plane
    • Management Plane Security When Building/Providing a Cloud Service
  • Business Continuity and Disaster Recovery
    • Business Continuity Within the Cloud Provider
    • Business Continuity for Loss of the Cloud Provider
    • Business Continuity For Private Cloud and Providers

Domain 7: Infrastructure Security

  • Cloud Network Virtualisation
  • How Security Changes With Cloud Networking
    • Challenges of Virtual Appliances
    • SDN Security Benefits
    • Microsegmentation and the Software Defined Perimeter
    • Additional Considerations for Cloud Providers or Private Clouds
    • Additional Considerations for Cloud Providers or Private Clouds
  • Cloud Compute and Workload Security
    • How Cloud Changes Workload Security
    • Immutable Workloads Enable Security
    • The Impact of Cloud on Standard Workload Security Controls
    • Changes to Workload Security Monitoring and Logging
    • Changes to Vulnerability Assessment
    • Cloud Storage Security

Domain 8: Virtualisation and Containers

  • Major Virtualisation Categories Relevant to Cloud Computing
    • Compute
  • Network
    • Monitoring and Filtering
    • Management Infrastructure
    • Cloud Overlay Networks
  • Storage
  • Containers

Domain 9: Incident Response

  • Incident Response Lifecycle
  • How the Cloud Impacts IR
    • Preparation
    • Detection and Analysis
    • Containment, Eradication and Recovery
    • Post-mortem

Domain 10: Application Security

  • Introduction to the Secure Software Development Lifecycle and Cloud Computing
  • Secure Design and Development
  • Secure Deployment
    • Impact on Vulnerability Assessment
    • Impact on Penetration Testing
    • Deployment Pipeline Security
    • Impact of Infrastructure as Code and Immutable
  • Secure Operations
  • How Cloud Impacts Application Design and Architectures
  • Additional Considerations for Cloud Providers
  • The Rise and Role of DevOps
    • Security Implications and Advantages

Domain 11: Data Security and Encryption

  • Data Security Controls
  • Cloud Data Storage Types
  • Managing Data Migrations to the Cloud
    • Securing Cloud Data Transfers
  • Securing Data in the Cloud
    • Cloud Data Access Controls
    • Storage (At-Rest) Encryption and Tokenization
    • Key Management (Including Customer-Managed Keys)
  • Data Security Architectures
  • Monitoring, Auditing, and Alerting
  • Additional Data Security Controls
    • Cloud Platform/Provider-Specific Controls
    • Data Loss Prevention
    • Enterprise Rights Management
    • Data Masking and Test Data Generation
  • Enforcing Lifecycle Management Security

Domain 12: Identity, Entitlement, and Access Management

  • How IAM is Different in the Cloud
  • IAM Standards for Cloud Computing
  • Managing Users and Identities for Cloud Computing
  • Authentication and Credentials
  • Entitlement and Access Management
  • Privileged User Management

Domain 13: Security as a Service

  • Potential Benefits and Concerns of SecaaS
  • Major Categories of Security as a Service Offerings
    • Identity, Entitlement, and Access Management Services
    • Cloud Access and Security Brokers (CASB, also known as Cloud Security Gateways)
    • Web Security (Web Security Gateways)
    • Email Security
    • Security Assessment
    • Web Application Firewalls
    • Intrusion Detection/Prevention (IDS/IPS)
    • Security Information & Event Management (SIEM)
    • Encryption and Key Management
    • Business Continuity and Disaster Recovery
    • Security Management
    • Distributed Denial of Service Protection

Domain 14: Related Technologies

  • Big Data
    • Security and Privacy Considerations
    • Data Collection
    • Key Management
    • Security Capabilities
    • Identity and Access Management
    • PaaS
  • Internet of Things (IoT)
  • Mobile
  • Serverless Computing

Exam Track

You'll sit the following exam at the Firebrand Training Centre, covered by your Certification Guarantee:

  • CSA Certificate of Cloud Security Knowledge (CCSK) exam

Additional exam information:

  • 60 online multiple choice questions
  • Time limit: 90 minutes
  • Pass rate: 80%

What's Included

Prerequisites

You should have a basic understanding of security fundamentals, such as firewalls, secure development, encryption and identity management.

Sind Sie sich unsicher, ob Sie die Voraussetzungen erfüllen? Wir besprechen gerne mit Ihnen Ihren technischen Hintergrund, Erfahrung und Qualifikation, um herauszufinden, ob dieser Intensivkurs der richtige für Sie ist.

Erfahrungsberichte

Bereits 76194 Kursteilnehmer haben seit 2001 erfolgreich einen Firebrand-Kurs absolviert. Unsere aktuellen Kundenbefragungen ergeben: Bei 96.74% unserer Teilnehmer wurde die Erwartungshaltung durch Firebrand übertroffen!

"Sehr guter Überblick über Azure Funktionsumfang und gut aufbereitet."
H.K., Appsfactory GmbH. (15.6.2020 (Montag) bis 20.6.2020 (Samstag))

"Sehr viel Wissen, kompakt in fünf Tagen, welches sehr gut vermittelt wurde. Unterkunft und Verpflegung waren sehr gut."
A.W.. (25.5.2020 (Montag) bis 30.5.2020 (Samstag))

"Meine Erfahrung war sehr gut und ich war sehr zufrieden. Ich komme gerne wieder für weitere Kursen"
A.L.. (25.5.2020 (Montag) bis 30.5.2020 (Samstag))

"Druckbetankung "at its best", wie der Instructor vielleicht sagen würde. Vermittelte Informationen wurden direkt via Tests, Labs und sporadisch gestellten Fragen überprüft und angewendet. Besser kann ich mir die Vorbereitung auf eine Prüfung nicht vorstellen. "
R.K.. (18.5.2020 (Montag) bis 20.5.2020 (Mittwoch))

"Jederzeit zu empfehlen! Der Trainer war unfassbar gut ausgebildet und konnte das Wissen anschaulich vermitteln."
Christian Klünter, TrueMask. (20.4.2020 (Montag) bis 25.4.2020 (Samstag))

Kurstermine

Start

Ende

Verfügbarkeit

Standort

Anmelden

25.5.2020 (Montag)

26.5.2020 (Dienstag)

Kurs gelaufen - Hinterlasse Kommentar

-

 

28.9.2020 (Montag)

29.9.2020 (Dienstag)

Warteliste

Überregional

 

9.11.2020 (Montag)

10.11.2020 (Dienstag)

Einige Plätze frei

Überregional

 

21.12.2020 (Montag)

22.12.2020 (Dienstag)

Einige Plätze frei

Überregional

 

1.2.2021 (Montag)

2.2.2021 (Dienstag)

Einige Plätze frei

Überregional

 

15.3.2021 (Montag)

16.3.2021 (Dienstag)

Einige Plätze frei

Überregional

 

Neueste Rezensionen von unseren Kursteilnehmern