|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/ccsp-domain-3-cloud-platform-and-infrastructure-security/
课程评论:没有评论
**课程名称:** CCSP Domain 3 - 云平台与基础设施安全 **课程概述:** 本课程全面深入地讲解了云平台与基础设施安全的关键概念,该领域占CCSP考试的17%。课程内容经过精心设计,旨在帮助学员掌握所需的知识点,并明确每个知识点的掌握深度。课程包含超过5小时的视频内容,并配有基于作者书籍《Cloud Guardians》的课程笔记。 **核心内容:** * **网络基础:** 课程会深入探讨网络在云数据中心中的作用,解释主流云服务提供商(如亚马逊)如何利用其网络提供服务。对于不熟悉网络基础知识(如交换机、路由器、IP地址等)的学员,课程特别提供了专门的视频章节进行讲解,并允许有基础的学员跳过。 * **风险管理:** 课程将详细介绍风险分析、评估和响应的各个环节,涵盖基本风险术语(如资产、威胁、风险偏好、风险容忍度)以及定量和定性风险评估方法。尽管考试不要求进行实际计算,但理解这些概念至关重要。 * **安全标准与实践:** 课程将简要介绍安全云联盟(Cloud Security Alliance)的“Egregious 11”和“Treacherous 12”文档。其中,“Treacherous 12”提供了对云安全问题的基本视角,“Egregious 11”则更偏向技术层面(尽管不及OWASP Top 10那样深入),这些文档揭示了当前云环境中的一些实际安全挑战。 * **业务连续性管理 (BCM):** 课程将从云环境的角度探讨业务连续性管理,重点在于云在BCM中的定位,而非深入讲解具体的站点恢复细节(如冷热站点)。学员需要熟练掌握与BCM相关的时间框架术语,例如最大可容忍中断时间(MTD)、恢复时间目标(RTO)和恢复点目标(RPO)等。 **学习目标:** 本课程旨在帮助学员全面理解CCSP考试中关于云平台与基础设施安全领域的核心知识,为通过考试奠定坚实基础。
In this course we walk through all of the critical concepts within the Cloud Platform & Infrastructure domain. This domain is 17% of the test. I will guide you through all of the concepts that you need to know and advise you on the level of knowledge that you need to get comfortable with.There is over 5 hours of video content plus course notes based on information from my book: Cloud Guardians.We will take a look at networking. At its core this is a data center class. It is current data center technology that allows companies like Amazon to sell services that live on their network. If you are not comfortable with the basics to how networks work it is essential to take a look. If you are familiar with switches, routers, IP and such I have separated out those video sections so that it is easier to breeze right on by.We will walk through risk analysis, evaluation and response. We will take a look at basic risk terms, from asset and threat to risk appetite and tolerance. It is also very good to know what quantitative and qualitative risk assessments are. You do not need to actually perform any calculations on the test at this time though.And a brief look at the Cloud Security Alliances Egregious 11 and Treacherous 12 documents. The Treacherous 12 is a pretty basic way to look at problems on the cloud, but the Egregious 11 gets a bit more technical. Not to the level that the OWASP Top 10 is at, but still good to spend a little time getting to know. They are the actual problems (at least some of them) that we have with the cloud today.We will also look at Business Continuity Management (BCM). It is an abbreviated view as we do not need to go into things like what is the difference between a hot site and a cold site. Instead the question is where does the cloud fit into BCM? Do make sure that you know your time frames e.g., MTD, RTO, RPO, etc.