Companion-course connectionCloud Logging and Forensic Readiness
Cloud forensic readiness ensures that logs, snapshots, metadata, identities, timestamps, and response procedures are available before an incident requires them.
Open article →Companion-course connectionCloud Logging and Monitoring
Cloud logging and monitoring collect, protect, correlate, and analyze events from identities, control planes, networks, workloads, applications, data services, and security tools.
Open article →Companion-course connectionCloud Threat Detection
Cloud threat detection identifies suspicious behavior across identities, control planes, workloads, networks, storage, and managed services.
Open article →Companion-course connectionImmutable Infrastructure
Immutable infrastructure replaces deployed components with newly built versions instead of modifying them in place.
Open article →Companion-course connectionCloud Control Plane Security
The cloud control plane contains the APIs, consoles, identities, and orchestration functions used to create and change cloud resources.
Open article →Companion-course connectionCloud IAM Policy Analysis
Cloud IAM policy analysis evaluates effective permissions, conditions, inheritance, wildcard use, trust relationships, resource scope, and paths to privilege escalation.
Open article →Companion-course connectionCloud Incident Response
Cloud incident response adapts preparation, detection, containment, eradication, and recovery to provider APIs, elastic resources, managed services, and shared responsibility.
Open article →Companion-course connectionCloud Interconnect Security
Cloud interconnect security protects dedicated and virtual connectivity between enterprise networks, cloud providers, exchanges, and software-defined interconnection services.
Open article →Companion-course connectionCloud Session and Token Security
Cloud session and token security governs issuance, scope, lifetime, storage, revocation, audience, refresh, and monitoring for interactive and workload access.
Open article →Companion-course connectionExposure
Exposure is the condition of being reachable, visible, accessible, or otherwise subject to loss or attack because assets, identities, data, or services are presented to a threat.
Open article →Companion-course connectionHypervisor Management-Plane Security
Hypervisor management-plane security protects the privileged interfaces, APIs, accounts, consoles, networks, and automation that can create, inspect, move, or control virtual workloads.
Open article →Companion-course connectionLateral Movement — MITRE ATT&CK® Tactic TA0008
Adversaries move from one account, system, workload, or trust zone to another using remote services, credentials, exploits, or transferred tools.
Open article →