CCSP Cert Prep: 4 Cloud Application Security

CCSP Cert Prep: 4 Cloud Application Security

2h 31mIntermediate2022-04-26

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Cloud-based applications are vulnerable to a wide range of attacks, from cross-site scripting (XSS) to session hijacking. Modern organizations need professionals who know how to build out application security programs that minimize such risks. Earning the Certified Cloud Security Professional (CCSP) certification validates that you have the knowledge necessary to secure applications wherever they are hosted. In this course, study for the fourth domain of the CCSP exam: Cloud Application Security with expert Mike Chapple. Learn about the development of software requirements and the use of different software development methodologies. Review some of the most notable application security vulnerabilities, as well as secure coding practices, strategies for identifying threats, and more.

Note: This course is designed to cover the most recent version of the CCSP exam, released in August 2022.

Skills covered

Cloud SecurityNetwork SecurityCert PrepCybersecurityCloud Computing

Concepts

Introduction

  • Securing cloud applications
  • What you need To know
  • Study resources

Secure Software Development Lifecycle

  • Development methodologies
  • Secure software development life cycle (SDLC)
  • Maturity models
  • Operation, maintenance, and change management
  • DevOps
  • SOA and microservices

Application Security Vulnerabilities

  • Common cloud vulnerabilities
  • Application security
  • Preventing SQL injection
  • Understanding cross-site scripting
  • Request forgery
  • Directory traversal
  • Overflow attacks
  • Cookies and attachments
  • Session hijacking
  • Code execution attacks
  • Privilege escalation

Secure Coding Practices

  • Secure coding guidance
  • Input validation
  • Parameterized queries
  • Authentication and session management issues
  • Output encoding
  • Error and exception handling
  • Code signing
  • Database security

Software Threat Assessment

  • Identifying threats
  • Risk analysis and mitigation
  • Threat modeling

Software Quality Assurance

  • Code review
  • Software testing
  • Code security tests
  • Abuse case testing
  • Fuzz testing
  • Code repositories
  • Application management

Verified Secure Software

  • Third party code
  • Acquired software
  • Developer training and awareness

Cloud Application Architecture

  • Building secure cloud solutions
  • Web application firewalls
  • Database security controls

Conclusion

  • Continuing your CCSP certification journey
80,000 Toman