Course Outline
Day 1: Cloud Security Foundations and Infrastructure Protection
Introduction to Cloud Security
- Core cloud computing concepts and characteristics
- Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)
- Public, private, hybrid, and multi-cloud environments
- Cloud actors and relationships with service providers
- Shared responsibility and shared fate models
- Benefits, limitations, and common misconceptions regarding cloud security
- Cloud attack surfaces and the current threat landscape
- Misconfiguration, exposed services, and insecure interfaces
- Cloud risk assessment and threat modelling
- Security considerations when selecting a cloud provider
Platform and Infrastructure Security
- Principles of secure cloud architecture
- Cloud landing zones and account structures
- Isolation in multi-tenant cloud environments
- Virtualization, virtual machines, and hypervisor security
- Security considerations for containers and serverless technologies
- Securing cloud management interfaces and administrative access
- Fundamentals of identity and access management
- Users, groups, roles, and service identities
- Role-based and attribute-based access control
- Least privilege and separation of duties
- Multifactor authentication and privileged access management
- Federation, single sign-on, and identity lifecycle management
- Network segmentation and micro-segmentation
- Virtual networks, subnets, routing, and security groups
- Cloud firewalls, web application firewalls, and distributed denial-of-service protection
- Secure connectivity between cloud and on-premises environments
- Infrastructure-as-code security and configuration baselines
Platform Examples
- AWS IAM, VPC, Security Groups, Network ACLs, and AWS Security Hub
- Microsoft Entra ID, Azure RBAC, Virtual Networks, Network Security Groups, and Microsoft Defender for Cloud
- Google Cloud IAM, VPC firewall controls, and Security Command Center
Practical Exercises
- Comparing shared responsibility across different cloud service models
- Reviewing an insecure multi-cloud architecture
- Creating a least-privilege access model
- Designing network segmentation for a cloud-hosted application
Day 2: Cloud Application and Data Security
Application Security in the Cloud
- Principles of cloud-native application security
- Integrating security into the software development lifecycle
- DevSecOps and shifting security left
- Secure application architecture and design
- Application threat modelling
- Secure coding considerations for cloud applications
- Protecting APIs and service endpoints
- Authentication and authorization for applications
- Web application firewall controls
- Protecting containers, images, and registries
- Serverless application security
- Dependency and software supply-chain risks
- Secrets management and credential protection
- Security testing in CI/CD pipelines
- Static, dynamic, and software-composition analysis
- Application logging and runtime protection
- Managing vulnerabilities in cloud applications
Data Security in the Cloud
- Cloud data types and classification
- The cloud data lifecycle
- Data ownership, location, and sovereignty
- Structured and unstructured cloud storage
- Securing object, block, file, and database storage
- Encryption at rest and in transit
- Key generation, storage, rotation, and revocation
- Customer-managed and provider-managed encryption keys
- Hardware security modules and key-management services
- Tokenization, masking, and pseudonymization
- Data loss prevention
- Storage access controls and public-access prevention
- Database security and activity monitoring
- Data retention and secure deletion
- Backup protection and ransomware resilience
- Privacy considerations in multi-cloud environments
Platform Examples
- AWS KMS, Secrets Manager, Macie, WAF, and storage security controls
- Azure Key Vault, Defender for Cloud, Azure Policy, and storage security controls
- Google Cloud KMS, Secret Manager, Cloud Armor, and data-protection controls
Practical Exercises
- Identifying security weaknesses in a cloud-hosted application
- Designing an application-secrets management process
- Reviewing insecure storage permissions
- Developing an encryption and key-management strategy
- Applying API and web application protection controls
Day 3: Cloud Operations and Authorized Security Testing
Operational Security in the Cloud
- Building a cloud security operating model
- Secure provisioning and decommissioning
- Asset discovery and inventory management
- Configuration and change management
- Cloud security posture management
- Establishing secure configuration baselines
- Patch and vulnerability management
- Workload and image hardening
- Centralized logging and monitoring
- Cloud-native audit logs
- Security information and event management integration
- Alert development and prioritization
- Threat intelligence in cloud environments
- Security metrics and reporting
- Continuous control monitoring
- Privileged activity monitoring
- Detecting configuration drift
- Managing third-party cloud services
- Cloud service-level agreements and security responsibilities
- Cost anomalies as potential security indicators
Cloud Vulnerability Assessment and Penetration Testing
- Cloud security assessment methodologies
- Rules of engagement and written authorization
- Understanding cloud-provider testing policies
- Defining assessment scope and boundaries
- Reconnaissance and cloud asset discovery
- Reviewing exposed storage and services
- Identity and privilege escalation risks
- Network and application security testing
- Container and serverless assessment considerations
- Reviewing infrastructure-as-code configurations
- Vulnerability validation and risk rating
- Avoiding disruption to shared cloud services
- Documenting evidence and findings
- Developing actionable remediation recommendations
- Retesting and verification
Practical Exercises
- Reviewing a cloud security baseline
- Investigating configuration drift
- Analysing cloud audit logs
- Developing an authorized cloud assessment plan
- Assessing a simulated cloud environment
- Prioritizing vulnerabilities and preparing remediation guidance
Day 4: Incident Response and Cloud Forensics
Incident Detection and Response
- Cloud incident-response principles
- Preparing a cloud incident-response plan
- Roles, responsibilities, and escalation procedures
- Cloud-specific indicators of compromise
- Detecting unauthorized access and privilege abuse
- Identifying compromised identities and access keys
- Detecting malicious workload and network activity
- Triage and incident classification
- Containment in elastic and distributed environments
- Credential revocation and session termination
- Workload isolation and snapshot preservation
- Eradication, recovery, and post-incident validation
- Security orchestration, automation, and response
- Integrating cloud alerts with SIEM and SOAR platforms
- Coordinating with cloud service providers
- Communication, notification, and reporting
- Post-incident review and lessons learned
Cloud Forensics
- Cloud forensic principles and challenges
- Legal authority and investigation boundaries
- Evidence sources in AWS, Azure, and GCP
- Audit, identity, network, application, and workload logs
- Volatile and persistent cloud evidence
- Collecting virtual machine snapshots and storage evidence
- Preserving logs and configuration records
- Evidence integrity and chain of custody
- Establishing an incident timeline
- Identity and access activity analysis
- Investigating compromised cloud workloads
- Forensic readiness in cloud architecture
- Limitations in multi-tenant and managed services
- Working with cloud providers during investigations
- Documenting and presenting investigation findings
Practical Exercises
- Investigating suspicious cloud identity activity
- Building an incident timeline from audit records
- Developing containment and recovery actions
- Preparing a cloud evidence-collection checklist
- Creating a cloud incident-response runbook
Day 5: Resilience, Governance, Compliance and Exam Preparation
Business Continuity and Disaster Recovery
- Cloud resilience and availability principles
- Business impact analysis
- Recovery time and recovery point objectives
- High availability, fault tolerance, and redundancy
- Backup, replication, and restoration strategies
- Cross-region and cross-cloud recovery
- Protecting backups from deletion and ransomware
- Disaster-recovery architecture patterns
- Failover and failback planning
- Testing cloud recovery procedures
- Provider outages and dependency risks
- Integrating cloud recovery with organizational continuity plans
Governance and Risk Management
- Cloud governance principles and operating models
- Defining cloud security policies and standards
- Establishing account, subscription, and project guardrails
- Cloud risk identification, analysis, and treatment
- Risk registers and control ownership
- Third-party and supply-chain risk
- Continuous compliance monitoring
- Cloud security assessments and audits
- Executive reporting and security metrics
- Governance considerations for multi-cloud environments
Compliance, Standards and Legal Considerations
- ISO/IEC 27001 and cloud security
- ISO/IEC 27017 cloud security controls
- ISO/IEC 27018 protection of personal data in public clouds
- PCI DSS considerations for cloud-hosted payment environments
- Privacy and data-protection requirements
- Data residency, sovereignty, and cross-border transfer
- Contractual responsibilities and right-to-audit provisions
- Electronic discovery and evidence preservation
- Cloud-provider compliance documentation
- Mapping technical controls to regulatory requirements
- Managing compliance across AWS, Azure, and GCP
Examination Preparation
- Reviewing the CCSE knowledge domains
- Identifying key concepts and terminology
- Approaching scenario-based questions
- Eliminating incorrect multiple-choice answers
- Time-management strategies
- Reviewing common areas of confusion
- Practice questions and guided explanations
- Developing an individual revision plan
- Final knowledge assessment
Practical Exercises
- Designing a cloud disaster-recovery strategy
- Mapping security controls to an applicable standard
- Creating a multi-cloud governance model
- Completing an exam-oriented knowledge assessment
- Reviewing answers and identifying areas for further study
Certification and Examination Information
This course is designed to support preparation for the EC-Council Certified Cloud Security Engineer examination.
According to EC-Council’s currently published information, the examination has:
- Exam code: 312-40
- Number of questions: 125
- Format: Multiple choice
- Duration: 4 hours
- Published passing score: 70%
- Delivery: EC-Council Exam Portal
The official public curriculum currently covers 11 areas ranging from cloud security foundations and infrastructure protection through application security, data protection, operations, testing, incident response, forensics, resilience, governance, and legal issues. It combines vendor-neutral concepts with AWS, Azure, and GCP security practices. EC-Council CCSE course and examination information
Important Notice
This is an independently developed NobleProg examination-preparation course. Unless expressly included in the commercial proposal:
- Official EC-Council courseware is not included.
- The EC-Council examination voucher is not included.
- Registration for the examination is not included.
- Participation does not automatically grant the CCSE certification.
- Participants receive a NobleProg e-certificate of completion after completing the training.
- The CCSE credential is awarded only by EC-Council after successfully meeting its certification requirements.
- Examination policies, content, and fees may change; candidates should verify the latest details directly with EC-Council before registering.
Requirements
Participants are expected to possess:
- A foundational understanding of cloud computing and standard cloud service models.
- Familiarity with at least one major cloud platform, ideally AWS, Azure, or GCP.
- Practical knowledge of networking concepts, including TCP/IP, DNS, routing, subnets, and firewalls.
- Basic knowledge of information security concepts, such as access control, encryption, vulnerabilities, and incident response.
- General experience with IT systems, infrastructure, or security administration.
Previous professional certification is not mandatory. While basic familiarity with command-line interfaces is advantageous for practical exercises, prior programming experience is not required.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6500 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
Cloud security standar