Content Areas Assessed & Domains

SANS Assessments are delivered through a web-based tool. There are 30 questions and users have 60 minutes to complete the Assessment. Online reports summarize each user’s results in detail. Cloud Security Assessments are $150 each with a minimum purchase of 25 total assessments.
Cloud Models and Fundamentals

The candidate will demonstrate their knowledge of the fundamental cloud terminology and models.

  • NIST Guidelines for Securing Cloud Technology
  • Multi-tenancy Considerations
  • Cloud Terminology
  • Common Attack Vectors
  • Cloud Deployment Models
  • Shared Responsibility Models
  • Service Models
  • Cloud Actors
Cloud Access Management and Auditing

The candidate will demonstrate their knowledge of cloud access management and fundamentals of audit logging.

  • Cloud Management Interfaces
  • Programmatic Access
  • Identity and Access Management
  • Logging Services
  • Cloud Security Tools
Cloud Application and Service Security

The candidate will demonstrate their knowledge of cloud hosted application and service security.

  • Secure Database Integration
  • Application Security
  • Secrets Management
  • Threat Modeling
  • Encryption
  • Denial of Service
  • Identity Federation
Cloud Architecture and Automation

The candidate will demonstrate their knowledge of architecting and hardening cloud resources in a secure and automated fashion using Infrastructure as Code.

  • Cloud Adoption Framework
  • Secure Architecture Considerations
  • Patch Management
  • Infrastructure-as-Code
  • Vulnerability Management
  • Segmentation and Isolation
Cloud Risk and Compliance

The candidate will demonstrate their knowledge of legal, compliance, and risk management considerations associated with cloud information security.

  • Security Assurance
  • Global Cloud Considerations
  • Incident Response
  • Penetration Testing
  • Legal and Contractual Requirements
  • Industry Standards and Frameworks