This certificate joins the two halves of federal cloud security into one path. It begins with fundamentals — cloud service and deployment models, the role FedRAMP plays in federal cloud governance, the shared responsibility model worked against real scenarios, and the essential identity, access and data-protection practices — establishing the vocabulary and governance context first. It then turns to architecture and operations, treating the design of a secure cloud and the work of keeping it secure as two distinct jobs.
The second half teaches from real incidents rather than theory. The 2024 Snowflake tenant breach and the Storm-0558 signing-key compromise are worked through in detail, because between them they cover the two failure modes that matter most: credentials without strong authentication on a non-SSO path, and compromise of a trust anchor itself. The path also carries material most cloud training has not caught up to — CNAPP broken into its real parts of CSPM, CWPP and CIEM, post-quantum cryptography migration for cloud key management, service mesh proxy architecture, CISA's SCuBA baselines, and FedRAMP's move to the 20x authorization model. It ends with a workshop where participants take a fictional cloud architecture and build a prioritized hardening plan they then have to defend.