Term 211
CloudWatch Events
CloudWatch Events is an AWS service that delivers a near real-time stream of system events describing changes in AWS resources and enables you to set up automated responses using rules.
Acronym study
Terms 211–240 of 1222 SK0-005 acronyms and key terms. Each entry includes a plain-English definition and a link to the full 800-word glossary page with exam context and practice questions.
Term 211
CloudWatch Events is an AWS service that delivers a near real-time stream of system events describing changes in AWS resources and enables you to set up automated responses using rules.
Term 212
A service from Amazon Web Services that lets you collect, monitor, and store log files from your AWS resources and applications.
Term 213
CloudWatch Logs Insights is a fully managed service within AWS that lets you interactively search, analyze, and query log data stored in Amazon CloudWatch Logs using a purpose-built query language.
Term 214
A CloudWatch metric is a time-ordered data point or set of data points that represents the performance, health, or operational state of an AWS resource, environment, or application.
Term 215
CMG (Cloud Management Gateway) is a Microsoft Intune component that lets you manage internet-based devices without a direct connection to your on-premises infrastructure.
Term 216
Co-management is a device management strategy that lets organizations simultaneously manage Windows 10 and later devices using both Configuration Manager (on-premises) and Microsoft Intune (cloud), enabling a gradual transition to modern management.
Term 217
Cobalt Strike is a commercial penetration testing tool used by security professionals to simulate advanced cyberattacks, but it is also widely abused by real adversaries for post-exploitation and command-and-control operations.
Term 218
CodeQL is a semantic code analysis engine used by developers to find security vulnerabilities in source code by treating code as data and querying it for potential flaws.
Term 219
Column-Level Security is a database feature that restricts access to specific columns in a table, allowing only authorized users to see sensitive data within those columns.
Term 220
Command injection is a security vulnerability where an attacker inserts malicious commands into a system through an input field, tricking the application into executing them on the underlying operating system.
Term 221
Common Criteria is an international standard (ISO 15408) that provides a common framework for evaluating the security features and capabilities of information technology products.
Term 222
Communication management is the process of planning, executing, and controlling the flow of information among project stakeholders to ensure clear, timely, and effective exchanges.
Term 223
Company Portal is a Microsoft app that gives employees a secure, self-service way to enroll devices, access company apps, and manage work resources from any device.
Term 224
Compartmented security mode is a multilevel security (MLS) system where subjects are cleared for all sensitivity levels but only have access to specific compartments of information based on their need-to-know.
Term 225
A compensating control is a security measure implemented to reduce risk when a primary control cannot be used or is insufficient.
Term 226
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Term 227
Compliance and regulations are the set of laws, rules, and standards that organizations must follow to ensure their operations are legal, ethical, and secure.
Term 228
A Compliance Manager is a tool or service that helps organizations assess, monitor, and improve their adherence to regulatory standards, industry frameworks, and internal policies.
Term 229
A compliance monitoring strategy is a planned approach to continuously check that an organization's systems, data, and processes follow legal, regulatory, and internal policy requirements.
Term 230
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
Term 231
A compliance scan is an automated security assessment that checks systems, networks, and applications against a defined set of regulatory or organizational standards to verify adherence to required policies.
Term 232
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Term 233
Computer Management is a built-in Microsoft Windows tool that gives IT professionals a central console to manage system components like disks, users, services, and event logs.
Term 234
Conditional Access integration is a security framework that evaluates signals such as user identity, location, device state, and application sensitivity to grant or block access to resources before a session is established.
Term 235
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Term 236
The CIA Triad is a foundational security model that ensures data is kept secret, unaltered, and accessible when needed.
Term 237
A configuration backup is a saved copy of a device's settings, such as router interfaces, firewall rules, or switch VLANs, that can be restored if the device fails or is misconfigured.
Term 238
A configuration baseline is a fixed reference point that documents the approved hardware, software, settings, and performance parameters of an IT system or network component at a specific point in time.
Term 239
Configuration drift is the gradual, unplanned change in a system's configuration settings over time, causing it to deviate from its original or desired state.
Term 240
Configuration management is the process of systematically tracking and controlling changes to a system's hardware, software, and settings to maintain consistency and reliability.