CCSP Cert Prep: 4 Cloud Application Security
2h 31mIntermediate2022-04-26
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Cloud-based applications are vulnerable to a wide range of attacks, from cross-site scripting (XSS) to session hijacking. Modern organizations need professionals who know how to build out application security programs that minimize such risks. Earning the Certified Cloud Security Professional (CCSP) certification validates that you have the knowledge necessary to secure applications wherever they are hosted. In this course, study for the fourth domain of the CCSP exam: Cloud Application Security with expert Mike Chapple. Learn about the development of software requirements and the use of different software development methodologies. Review some of the most notable application security vulnerabilities, as well as secure coding practices, strategies for identifying threats, and more.
Note: This course is designed to cover the most recent version of the CCSP exam, released in August 2022.
Note: This course is designed to cover the most recent version of the CCSP exam, released in August 2022.
Skills covered
Cloud SecurityNetwork SecurityCybersecurityCert PrepCloud Computing
Concepts
0. Introduction
- 01 - Securing cloud applications
- 02 - What you need To know
- 03 - Study resources
1. Secure Software Development Lifecycle
- 04 - Development methodologies
- 05 - Secure software development life cycle (SDLC)
- 06 - Maturity models
- 07 - Operation, maintenance, and change management
- 08 - DevOps
- 09 - SOA and microservices
2. Application Security Vulnerabilities
- 10 - Common cloud vulnerabilities
- 11 - Application security
- 12 - Preventing SQL injection
- 13 - Understanding cross-site scripting
- 14 - Request forgery
- 15 - Directory traversal
- 16 - Overflow attacks
- 17 - Cookies and attachments
- 18 - Session hijacking
- 19 - Code execution attacks
- 20 - Privilege escalation
3. Secure Coding Practices
- 21 - Secure coding guidance
- 22 - Input validation
- 23 - Parameterized queries
- 24 - Authentication and session management issues
- 25 - Output encoding
- 26 - Error and exception handling
- 27 - Code signing
- 28 - Database security
4. Software Threat Assessment
- 29 - Identifying threats
- 30 - Risk analysis and mitigation
- 31 - Threat modeling
5. Software Quality Assurance
- 32 - Code review
- 33 - Software testing
- 34 - Code security tests
- 35 - Abuse case testing
- 36 - Fuzz testing
- 37 - Code repositories
- 38 - Application management
6. Verified Secure Software
- 39 - Third party code
- 40 - Acquired software
- 41 - Developer training and awareness
7. Cloud Application Architecture
- 42 - Building secure cloud solutions
- 43 - Web application firewalls
- 44 - Database security controls
Conclusion
- 45 - Continuing your CCSP certification journey