CCSP · domain
Cloud Platform and Infrastructure Security
This domain covers securing cloud infrastructure: compute, containers, networking, and storage. It tests how you design isolation, identity, and network controls across IaaS and managed platforms, and how you harden Kubernetes, VPCs, and virtual machines against privilege escalation, breakout, and data exposure.
Focused practice
Practice Cloud Platform and Infrastructure Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Platform and Infrastructure Security
You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.
Kubernetes hardening: Pod Security Admission, securityContext, seccomp/AppArmor, read-only root filesystems, dropping Linux capabilities.
AWS network controls: security groups, NACLs, VPC endpoints, PrivateLink, NAT gateways, and route table isolation.
Compute isolation: EC2 tenancy, dedicated hosts, instance metadata service (IMDSv2), and hypervisor separation.
Storage and data protection: KMS encryption, S3 bucket policies, EBS snapshots, and key rotation.
Watch out for
Common Cloud Platform and Infrastructure Security exam traps
- ▸Confusing security groups (stateful, instance-level allow rules) with NACLs (stateless, subnet-level allow/deny rules).
- ▸Assuming Kubernetes NetworkPolicy alone isolates pods; it requires a CNI that enforces it and does not replace authentication.
- ▸Forgetting that IMDSv1 is vulnerable to SSRF; IMDSv2 uses session tokens and should be enforced on EC2 instances.
Question index
All Cloud Platform and Infrastructure Security questions (111)
Click any question to see the full explanation, or start a practice session above.
A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?
Hard2A cloud security engineer is concerned about VM escape attacks in a multi-tenant environment. Which of the following is the most effective mitigation strategy?
Medium3A company is deploying a multi-tier application on AWS. They need to protect the application layer from common web attacks and also restrict traffic between tiers. Which TWO network security controls should they use?
Medium4A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?
Hard5A cloud security team is implementing VPC peering between two VPCs in the same region. Which statement about VPC peering is correct?
Medium6A cloud security architect is designing the network segmentation for a three-tier web application hosted in a single Amazon VPC. The database tier must accept connections only from the application tier, and the application tier must accept connections only from the web tier. The architect wants the enforcement to be stateful, evaluated per elastic network interface, and independent of subnet CIDR ranges so that instances can be replaced without rewriting rules. Which control should the architect use to enforce this segmentation?
Medium7Which container image security practice is most effective at reducing the attack surface by removing unnecessary components and lowering the number of CVEs?
Medium8A cloud security engineer is responsible for securing a serverless application built on AWS Lambda. The application processes sensitive customer data and writes results to an Amazon S3 bucket. The engineer must ensure that the Lambda function has only the permissions it needs to write to that specific bucket, and that the credentials are not hardcoded. Which approach should the engineer take?
Hard9A cloud security architect is designing a multi-tenant SaaS platform hosted on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application instance in one tenant's environment cannot decrypt another tenant's data. The architect wants to use AWS Key Management Service (KMS) to manage encryption keys. Which approach BEST meets this requirement?
Medium10Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?
Easy11A Kubernetes cluster is being hardened. Which THREE measures should be implemented to restrict container capabilities and reduce the risk of privilege escalation? (Select three.)
Hard12Which of the following is the primary security risk associated with VM escape in a cloud environment?
Easy13A financial services firm runs a multi-tenant SaaS platform on AWS. A penetration test reveals that a compromised container on one tenant's node was able to read environment variables belonging to another tenant's pods scheduled on the same node. The platform uses Kubernetes with default settings, and pods are not configured with any security context. Which control most directly addresses this isolation failure?
Hard14Which hypervisor type is most commonly deployed in production cloud data centers to host multiple tenant virtual machines?
Easy15A cloud security team is deploying a web application with an API Gateway. Which TWO mechanisms should be implemented to protect against API abuse and unauthorized access?
Medium16A security architect is designing a multi-tenant cloud environment. Which type of hypervisor provides the strongest isolation for tenant virtual machines by running directly on the hardware without a host operating system?
Easy17In a Kubernetes cluster, which resource should be used to restrict network traffic between pods based on source and destination labels?
Medium18A cloud security team is evaluating controls for protecting data in a PaaS database service. The database must support tenant isolation, and the team wants to prevent one tenant's queries from accessing another tenant's rows. Which TWO controls BEST achieve row-level tenant isolation? (Choose two.)
Medium19An organization exposes an API via Amazon API Gateway. They need to protect against common web exploits like SQL injection and cross-site scripting. Which integration should they enable?
Medium20A security auditor is reviewing a Kubernetes cluster and identifies that containers are running as root with full Linux capabilities. Which TWO security measures would help mitigate container escape risks in this environment?
Medium21A DevOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and prevent tampering?
Hard22A healthcare organization stores PHI in an Amazon S3 bucket. An auditor finds that objects are encrypted with SSE-S3, and the organization wants to demonstrate that it controls the encryption keys and can audit their use independently of AWS-managed keys. Which change best satisfies this requirement while minimizing application changes?
Medium23A financial services company runs a regulated workload on a public cloud. The security team must ensure that all data at rest in the cloud provider's block storage service is encrypted with keys that the company controls and can revoke immediately. The company also needs to prove to auditors that the cloud provider cannot access the plaintext data. Which approach BEST meets these requirements?
Hard24A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?
Hard25A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?
Hard26A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?
Easy27A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?
Medium28A cloud operations team is configuring a virtual private cloud (VPC) and needs to control both inbound and outbound traffic at the subnet level. The team wants to ensure that any traffic leaving the subnet is explicitly allowed, and that responses to inbound requests are automatically permitted. Which VPC component should the team configure?
Easy29Which of the following is a primary benefit of using immutable tags for container images in a production registry?
Easy30In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?
Easy31Which hypervisor technology is used to provide direct device access to a VM, improving performance and isolation for I/O operations?
Easy32A cloud security architect is designing a multi-tenant environment on a hypervisor. Which hypervisor type provides the most robust isolation between tenant virtual machines by running directly on the hardware without a host operating system?
Easy33During an audit of a containerized application, you notice that containers are running with the --privileged flag. Which of the following is the most significant security risk associated with this configuration?
Medium34A company is deploying a serverless function in AWS Lambda that needs to access a private RDS database. Which TWO configurations are necessary for secure access?
Easy35A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?
Hard36A cloud security engineer is implementing API Gateway security for a public-facing API. Which combination of controls best protects against both injection attacks and excessive usage?
Hard37A financial services company runs sensitive workloads on a public IaaS cloud. The security team wants to cryptographically prove to auditors that the virtual machine hosting their data booted an unmodified, approved hypervisor and firmware image. Which cloud infrastructure security capability should they require from the provider?
Medium38A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?
Medium39A security team implements Kubernetes RBAC. They want to ensure that a service account can only create pods in the 'dev' namespace. Which RBAC resource should they use?
Medium40A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing kubelet and container runtime configurations. Which TWO of the following measures are MOST effective at reducing the attack surface and preventing a compromised container from gaining node-level privileges? (Choose two.)
Hard41An organization uses Azure Functions and wants to secure its API endpoints exposed via Azure API Management. Which TWO security controls should they implement at the API Gateway level?
Medium42A cloud security team is using AWS Lambda functions to process sensitive data. The functions are triggered by Amazon S3 events and write to an Amazon DynamoDB table. The team wants to ensure that the Lambda functions have only the permissions they need and that any compromised function cannot access other AWS resources. Which of the following is the MOST effective approach?
Hard43A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)
Hard44A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?
Medium45A DevOps engineer is configuring a Kubernetes cluster and wants to enforce that containers cannot run as root and cannot mount host paths. Which Kubernetes security mechanism should be used?
Medium46A security team is hardening a Kubernetes cluster for production workloads. Which THREE measures should they implement to improve runtime container security?
Medium47A cloud security engineer is designing network isolation for a multi-tier application in a single VPC. The database tier must accept connections only from the application tier, and the application tier must accept traffic only from the web tier. Which mechanism should the engineer use to enforce this at the instance level?
Hard48A cloud operations team is deploying a three-tier application across two AWS Availability Zones. The database tier must not be reachable from the internet, and the web tier must accept HTTPS from the public. The security architect wants defense in depth at both the subnet and instance levels. Which combination of controls BEST aligns with a layered network security design?
Hard49A serverless function needs to access a private database service without traversing the public internet. Which configuration should be used?
Easy50Which of the following is a primary risk specific to virtual machine escape attacks in cloud environments?
Easy51A security engineer is implementing container image security. They want to ensure that only signed images from a trusted registry can be deployed in the Kubernetes cluster. Which tool should they use to enforce this at the admission controller level?
Medium52In a Kubernetes environment, a security team wants to enforce that only images signed by a trusted authority can be deployed. Which component can be used to validate image signatures at admission time?
Hard53A security analyst discovers that a container running in a Kubernetes cluster has been compromised. The attacker escalated privileges and accessed the host's kernel. Which of the following misconfigurations most likely allowed this container escape?
Hard54A cloud security architect needs to allow an application in a VPC to access a cloud database service without traversing the public internet. Which feature should be implemented?
Medium55A company is migrating a legacy application to a cloud provider's infrastructure as a service (IaaS) platform. The security team must ensure that the hypervisor layer is patched and secured, and that tenants cannot access each other's memory or storage. According to the shared responsibility model, which party is responsible for securing the hypervisor and preventing cross-tenant access?
Medium56A company is adopting a microservices architecture on Kubernetes and needs to ensure least privilege for pod-to-pod communication. Which THREE controls should be implemented?
Hard57A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?
Medium58A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?
Hard59A cloud operations team is deploying a web application behind a load balancer in a VPC. The application servers must be reachable only from the load balancer, never directly from the internet. Which configuration achieves this?
Easy60A cloud security team is designing the management plane for a regulated workload on a public IaaS platform. They must ensure that administrative access to the cloud console and APIs is strongly controlled. Which TWO measures best satisfy this requirement? (Choose two.)
Hard61Which of the following is a key difference between a security group and a network ACL in a VPC?
Easy62A company uses Azure Functions for serverless data processing. To securely access an Azure SQL database, which of the following is the most secure method for managing the database connection string?
Medium63A startup is designing its first cloud landing zone and wants a guardrail that prevents any principal in the organization from disabling AWS CloudTrail logging in any account, including the management account, while still allowing normal administrative work. Which control achieves this with the LEAST operational overhead?
Easy64A cloud security team is designing network security for a multi-VPC architecture in AWS. Which TWO of the following are valid considerations for VPC peering?
Medium65A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?
Easy66A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?
Medium67A healthcare organization runs a regulated workload on a public cloud. The security team must ensure that data stored in object storage remains unreadable to the cloud provider's staff even if they have physical access to the storage media. Which approach best meets this requirement?
Medium68In a cloud environment using KVM, a security auditor wants to ensure that a tenant VM cannot access the memory of another tenant VM on the same physical host. Which resource isolation mechanism is specifically designed to prevent such memory access?
Hard69A cloud architect is designing VPC connectivity for a global organization with multiple AWS accounts. They need a central hub for connecting many VPCs together, supporting transitive routing. Which service should they use?
Hard70A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?
Medium71A cloud security architect is hardening the metadata service on a fleet of EC2 instances that host a customer-facing web application. The team wants to reduce the risk of server-side request forgery leading to credential theft, while keeping the application's legitimate ability to retrieve instance role credentials. Which TWO measures should the architect implement? (Choose two.)
Hard72A cloud security architect is designing a multi-tenant virtualized environment. Which type of hypervisor is considered most secure for cloud deployments due to its reduced attack surface and direct hardware control?
Easy73A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?
Medium74A cloud security engineer is configuring an Amazon S3 bucket that must store sensitive financial data. The requirement is that all data must be encrypted at rest with keys that the organization controls and can rotate, and that access to the keys must be auditable and separable from the data access permissions. Which S3 encryption option BEST meets these requirements?
Medium75A security analyst is configuring an API Gateway for a cloud application. The application must handle high traffic and prevent abuse from a single client. Which feature should the analyst enable to limit the number of requests from a client within a specified time window?
Medium76A cloud security engineer is hardening container runtime environments. Which TWO of the following are effective measures to prevent container escape?
Medium77A cloud security professional is concerned about VM escape attacks. Which mitigation is most effective?
Easy78An organization uses Azure Functions and needs to ensure that the function can securely access a database in a private VNet. What is the recommended approach?
Medium79A financial services company is migrating its cardholder data environment to a public cloud IaaS platform. The security team must determine which controls remain the customer's responsibility under the shared responsibility model. Which of the following is the customer's responsibility in this IaaS deployment?
Easy80A cloud architect is designing a multi-tenant environment. To ensure that a tenant's virtual machine cannot access another tenant's memory, which resource isolation technique should be enforced at the hypervisor level?
Hard81Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)
Easy82A healthcare company is migrating a legacy three-tier application to AWS. The security team must ensure that the database tier is reachable only from the application tier, that the rule follows the application instances automatically as they scale, and that no rule permits a broader source. Which mechanism should the team use?
Medium83During a security review of a serverless application, you notice that a Lambda function's execution role has permissions to delete all S3 buckets in the account. What is the most appropriate remediation to align with the principle of least privilege?
Hard84During a supply chain security review, a team discovers that container images are not being verified at admission time. Which Kubernetes-native tool should be implemented to ensure only signed images are deployed?
Hard85A cloud security team is reviewing container security practices. Which of the following is the most effective way to minimize the attack surface of a container image?
Easy86A cloud security architect is designing a workload that must store encryption keys in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. The workload runs on a major public cloud provider. The architect wants to minimize operational overhead while ensuring the keys never leave the HSM boundary. Which cloud service model should the architect select?
Medium87A cloud provider offers a virtual private cloud (VPC) with a subnet that hosts a database. A security architect must ensure that only instances in a specific application security group can connect to the database on port 3306, and that no other traffic from the internet or other subnets can reach it. The architect is configuring security groups and network ACLs. Which combination of rules BEST achieves this?
Hard88A cloud security administrator is responsible for managing access to a cloud management console. The organization wants to enforce multi-factor authentication (MFA) for all human users and ensure that programmatic access uses short-lived credentials instead of long-term access keys. Which approach BEST aligns with these requirements?
Easy89A cloud security team wants to enforce that only signed container images are deployed in their Kubernetes cluster. Which admission controller can validate image signatures at deploy time?
Hard90A cloud security team needs to ensure that an Amazon EC2 instance hosting a regulated workload cannot communicate with the public internet, but the instance must still be able to download OS patches from an internal repository and retrieve secrets from AWS Secrets Manager. The workload runs in a private subnet with no NAT gateway or internet gateway route. Which combination of configurations will meet these requirements with the LEAST operational overhead?
Medium91A cloud operations team runs a web tier on 40 Amazon EC2 instances behind an Application Load Balancer. Auditors require that administrators never hold long-lived SSH keys and that every login to an instance is logged with the identity of the human who initiated it. The team already uses an external SAML 2.0 identity provider for console access. Which approach BEST satisfies the auditors' requirements?
Medium92A financial services firm runs a regulated workload on a public cloud. Auditors require evidence that the cloud provider's physical security controls meet the firm's requirements. Which artifact provides the MOST direct evidence?
Hard93A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to ensure that a compromised pod cannot reach the cloud provider's instance metadata service to steal node credentials. Which control BEST addresses this?
Hard94A security engineer is reviewing container security practices. Which tool is specifically designed to scan container images for Common Vulnerabilities and Exposures (CVEs)?
Easy95A company uses AWS and needs to allow a Lambda function in a VPC to access an S3 bucket without traversing the internet. Which solution meets this requirement securely?
Hard96During a security assessment of a Kubernetes cluster, you discover that a container is running as root with privileged mode enabled. Which of the following is the most critical risk associated with this configuration?
Hard97A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?
Hard98A cloud security professional is evaluating container runtime security. Which Linux capability should be dropped from a container to prevent it from loading kernel modules?
Easy99A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?
Easy100A security engineer is concerned about a scenario where a malicious process inside a VM breaks out of the virtualized environment to compromise the hypervisor. What is this attack called and what is the primary mitigation?
Medium101A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application process cannot read another tenant's data. The architect plans to use AWS Key Management Service (KMS) with tenant-specific keys. Which of the following is the MOST critical security control to implement to achieve this isolation?
Medium102A healthcare cloud tenant must ensure that when a physical host is decommissioned, residual data in storage cannot be reconstructed. The provider offers self-encrypting drives. Which property most directly guarantees that cryptographic erasure is effective?
Hard103A security architect is designing a container runtime security strategy. Which of the following controls is most effective at preventing a container from compromising the host kernel?
Medium104A security architect is designing a VPC for a three-tier web application. Which of the following VPC subnet designs provides the most secure isolation for the database tier?
Medium105A financial services firm runs regulated workloads on Microsoft Azure. Auditors require that disk encryption keys for IaaS virtual machines remain under the firm's exclusive control, that the keys never leave a hardware security module, and that the firm can revoke access to the keys at any time, rendering the disks unreadable. The firm does not want Microsoft to be able to decrypt the disks without an explicit grant. Which Azure disk encryption configuration meets these requirements?
Hard106A cloud security auditor is reviewing container runtime configurations. Which TWO practices help prevent a container from compromising the host operating system?
Medium107A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?
Medium108A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?
Hard109A cloud security architect is designing a multi-tenant environment using Type 1 hypervisors. Which of the following is the primary security risk associated with this architecture?
Medium110A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which AWS network security component should they use?
Medium111A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is logically isolated and that a compromised tenant cannot access another tenant's resources. The architect decides to use separate AWS accounts per tenant and wants to centralize security management. Which AWS service should be used to manage these accounts and apply security policies centrally?
MediumOther domains
All CCSP exam domains
Frequently asked questions
- What does the Cloud Platform and Infrastructure Security domain cover on the CCSP exam?
- You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.
- How many questions are in this domain?
- This page lists all 111 Cloud Platform and Infrastructure Security questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Platform and Infrastructure Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.