Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A financial services company runs sensitive workloads on a public IaaS cloud. The security team wants to cryptographically prove to auditors that the virtual machine hosting their data booted an unmodified, approved hypervisor and firmware image. Which cloud infrastructure security capability should they require from the provider?

⚠ Common exam trap

The trap here is assuming that guest-level controls such as disk encryption or hardened images can attest to the integrity of the provider-controlled hypervisor and firmware beneath them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Measured boot with attestation using a virtual TPM

Measured boot combined with remote attestation uses a virtual TPM to hash each stage of the boot chain and expose those measurements for verification. Because the auditor needs cryptographic proof that firmware and hypervisor code were unmodified, this is the only listed control that observes the platform boot itself rather than the guest workload or network perimeter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Full-disk encryption of the guest operating system volumes

    Why it's wrong here

    Encrypting guest volumes protects data confidentiality if the underlying storage media is exposed, but it does nothing to prove that the hypervisor or firmware itself booted in an approved state. A compromised hypervisor could still decrypt and read guest memory, so this control does not deliver the platform integrity evidence the auditors are demanding.

  • ✓

    Measured boot with attestation using a virtual TPM

    Why this is correct

    A virtual TPM records hashes of firmware, bootloader, and hypervisor components into platform configuration registers during the boot chain, and remote attestation lets the tenant verify those measurements against a known-good baseline. This gives cryptographic evidence that the platform was not tampered with, directly satisfying the auditor's requirement for proof of an untampered boot.

  • ✗

    Security groups restricting inbound management ports

    Why it's wrong here

    Security groups are stateful packet filters that limit network reachability to instances, which reduces exposure to remote attacks. However, they provide no cryptographic measurement or proof of what code executed at boot, so they cannot demonstrate to auditors that the hypervisor and firmware were unmodified. This is a network control, not a platform integrity control.

  • ✗

    Immutable infrastructure with golden VM images

    Why it's wrong here

    Golden images standardize the guest operating system contents and reduce configuration drift, but the hypervisor and firmware sit beneath the guest and are controlled by the provider, not the image. Rebuilding instances from a template therefore cannot prove the underlying platform booted approved code, leaving the audit requirement unmet.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.