Courseiva

CCSP · domain

Cloud Platform and Infrastructure Security

This domain covers securing cloud infrastructure: compute, containers, networking, and storage. It tests how you design isolation, identity, and network controls across IaaS and managed platforms, and how you harden Kubernetes, VPCs, and virtual machines against privilege escalation, breakout, and data exposure.

111 questions26 easy48 medium37 hard

Focused practice

Practice Cloud Platform and Infrastructure Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Platform and Infrastructure Security

You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.

Kubernetes hardening: Pod Security Admission, securityContext, seccomp/AppArmor, read-only root filesystems, dropping Linux capabilities.

AWS network controls: security groups, NACLs, VPC endpoints, PrivateLink, NAT gateways, and route table isolation.

Compute isolation: EC2 tenancy, dedicated hosts, instance metadata service (IMDSv2), and hypervisor separation.

Storage and data protection: KMS encryption, S3 bucket policies, EBS snapshots, and key rotation.

Watch out for

Common Cloud Platform and Infrastructure Security exam traps

  • ▸Confusing security groups (stateful, instance-level allow rules) with NACLs (stateless, subnet-level allow/deny rules).
  • ▸Assuming Kubernetes NetworkPolicy alone isolates pods; it requires a CNI that enforces it and does not replace authentication.
  • ▸Forgetting that IMDSv1 is vulnerable to SSRF; IMDSv2 uses session tokens and should be enforced on EC2 instances.

Question index

All Cloud Platform and Infrastructure Security questions (111)

Click any question to see the full explanation, or start a practice session above.

1

A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?

Hard
2

A cloud security engineer is concerned about VM escape attacks in a multi-tenant environment. Which of the following is the most effective mitigation strategy?

Medium
3

A company is deploying a multi-tier application on AWS. They need to protect the application layer from common web attacks and also restrict traffic between tiers. Which TWO network security controls should they use?

Medium
4

A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?

Hard
5

A cloud security team is implementing VPC peering between two VPCs in the same region. Which statement about VPC peering is correct?

Medium
6

A cloud security architect is designing the network segmentation for a three-tier web application hosted in a single Amazon VPC. The database tier must accept connections only from the application tier, and the application tier must accept connections only from the web tier. The architect wants the enforcement to be stateful, evaluated per elastic network interface, and independent of subnet CIDR ranges so that instances can be replaced without rewriting rules. Which control should the architect use to enforce this segmentation?

Medium
7

Which container image security practice is most effective at reducing the attack surface by removing unnecessary components and lowering the number of CVEs?

Medium
8

A cloud security engineer is responsible for securing a serverless application built on AWS Lambda. The application processes sensitive customer data and writes results to an Amazon S3 bucket. The engineer must ensure that the Lambda function has only the permissions it needs to write to that specific bucket, and that the credentials are not hardcoded. Which approach should the engineer take?

Hard
9

A cloud security architect is designing a multi-tenant SaaS platform hosted on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application instance in one tenant's environment cannot decrypt another tenant's data. The architect wants to use AWS Key Management Service (KMS) to manage encryption keys. Which approach BEST meets this requirement?

Medium
10

Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?

Easy
11

A Kubernetes cluster is being hardened. Which THREE measures should be implemented to restrict container capabilities and reduce the risk of privilege escalation? (Select three.)

Hard
12

Which of the following is the primary security risk associated with VM escape in a cloud environment?

Easy
13

A financial services firm runs a multi-tenant SaaS platform on AWS. A penetration test reveals that a compromised container on one tenant's node was able to read environment variables belonging to another tenant's pods scheduled on the same node. The platform uses Kubernetes with default settings, and pods are not configured with any security context. Which control most directly addresses this isolation failure?

Hard
14

Which hypervisor type is most commonly deployed in production cloud data centers to host multiple tenant virtual machines?

Easy
15

A cloud security team is deploying a web application with an API Gateway. Which TWO mechanisms should be implemented to protect against API abuse and unauthorized access?

Medium
16

A security architect is designing a multi-tenant cloud environment. Which type of hypervisor provides the strongest isolation for tenant virtual machines by running directly on the hardware without a host operating system?

Easy
17

In a Kubernetes cluster, which resource should be used to restrict network traffic between pods based on source and destination labels?

Medium
18

A cloud security team is evaluating controls for protecting data in a PaaS database service. The database must support tenant isolation, and the team wants to prevent one tenant's queries from accessing another tenant's rows. Which TWO controls BEST achieve row-level tenant isolation? (Choose two.)

Medium
19

An organization exposes an API via Amazon API Gateway. They need to protect against common web exploits like SQL injection and cross-site scripting. Which integration should they enable?

Medium
20

A security auditor is reviewing a Kubernetes cluster and identifies that containers are running as root with full Linux capabilities. Which TWO security measures would help mitigate container escape risks in this environment?

Medium
21

A DevOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and prevent tampering?

Hard
22

A healthcare organization stores PHI in an Amazon S3 bucket. An auditor finds that objects are encrypted with SSE-S3, and the organization wants to demonstrate that it controls the encryption keys and can audit their use independently of AWS-managed keys. Which change best satisfies this requirement while minimizing application changes?

Medium
23

A financial services company runs a regulated workload on a public cloud. The security team must ensure that all data at rest in the cloud provider's block storage service is encrypted with keys that the company controls and can revoke immediately. The company also needs to prove to auditors that the cloud provider cannot access the plaintext data. Which approach BEST meets these requirements?

Hard
24

A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?

Hard
25

A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?

Hard
26

A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?

Easy
27

A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?

Medium
28

A cloud operations team is configuring a virtual private cloud (VPC) and needs to control both inbound and outbound traffic at the subnet level. The team wants to ensure that any traffic leaving the subnet is explicitly allowed, and that responses to inbound requests are automatically permitted. Which VPC component should the team configure?

Easy
29

Which of the following is a primary benefit of using immutable tags for container images in a production registry?

Easy
30

In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?

Easy
31

Which hypervisor technology is used to provide direct device access to a VM, improving performance and isolation for I/O operations?

Easy
32

A cloud security architect is designing a multi-tenant environment on a hypervisor. Which hypervisor type provides the most robust isolation between tenant virtual machines by running directly on the hardware without a host operating system?

Easy
33

During an audit of a containerized application, you notice that containers are running with the --privileged flag. Which of the following is the most significant security risk associated with this configuration?

Medium
34

A company is deploying a serverless function in AWS Lambda that needs to access a private RDS database. Which TWO configurations are necessary for secure access?

Easy
35

A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?

Hard
36

A cloud security engineer is implementing API Gateway security for a public-facing API. Which combination of controls best protects against both injection attacks and excessive usage?

Hard
37

A financial services company runs sensitive workloads on a public IaaS cloud. The security team wants to cryptographically prove to auditors that the virtual machine hosting their data booted an unmodified, approved hypervisor and firmware image. Which cloud infrastructure security capability should they require from the provider?

Medium
38

A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?

Medium
39

A security team implements Kubernetes RBAC. They want to ensure that a service account can only create pods in the 'dev' namespace. Which RBAC resource should they use?

Medium
40

A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing kubelet and container runtime configurations. Which TWO of the following measures are MOST effective at reducing the attack surface and preventing a compromised container from gaining node-level privileges? (Choose two.)

Hard
41

An organization uses Azure Functions and wants to secure its API endpoints exposed via Azure API Management. Which TWO security controls should they implement at the API Gateway level?

Medium
42

A cloud security team is using AWS Lambda functions to process sensitive data. The functions are triggered by Amazon S3 events and write to an Amazon DynamoDB table. The team wants to ensure that the Lambda functions have only the permissions they need and that any compromised function cannot access other AWS resources. Which of the following is the MOST effective approach?

Hard
43

A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)

Hard
44

A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?

Medium
45

A DevOps engineer is configuring a Kubernetes cluster and wants to enforce that containers cannot run as root and cannot mount host paths. Which Kubernetes security mechanism should be used?

Medium
46

A security team is hardening a Kubernetes cluster for production workloads. Which THREE measures should they implement to improve runtime container security?

Medium
47

A cloud security engineer is designing network isolation for a multi-tier application in a single VPC. The database tier must accept connections only from the application tier, and the application tier must accept traffic only from the web tier. Which mechanism should the engineer use to enforce this at the instance level?

Hard
48

A cloud operations team is deploying a three-tier application across two AWS Availability Zones. The database tier must not be reachable from the internet, and the web tier must accept HTTPS from the public. The security architect wants defense in depth at both the subnet and instance levels. Which combination of controls BEST aligns with a layered network security design?

Hard
49

A serverless function needs to access a private database service without traversing the public internet. Which configuration should be used?

Easy
50

Which of the following is a primary risk specific to virtual machine escape attacks in cloud environments?

Easy
51

A security engineer is implementing container image security. They want to ensure that only signed images from a trusted registry can be deployed in the Kubernetes cluster. Which tool should they use to enforce this at the admission controller level?

Medium
52

In a Kubernetes environment, a security team wants to enforce that only images signed by a trusted authority can be deployed. Which component can be used to validate image signatures at admission time?

Hard
53

A security analyst discovers that a container running in a Kubernetes cluster has been compromised. The attacker escalated privileges and accessed the host's kernel. Which of the following misconfigurations most likely allowed this container escape?

Hard
54

A cloud security architect needs to allow an application in a VPC to access a cloud database service without traversing the public internet. Which feature should be implemented?

Medium
55

A company is migrating a legacy application to a cloud provider's infrastructure as a service (IaaS) platform. The security team must ensure that the hypervisor layer is patched and secured, and that tenants cannot access each other's memory or storage. According to the shared responsibility model, which party is responsible for securing the hypervisor and preventing cross-tenant access?

Medium
56

A company is adopting a microservices architecture on Kubernetes and needs to ensure least privilege for pod-to-pod communication. Which THREE controls should be implemented?

Hard
57

A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?

Medium
58

A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?

Hard
59

A cloud operations team is deploying a web application behind a load balancer in a VPC. The application servers must be reachable only from the load balancer, never directly from the internet. Which configuration achieves this?

Easy
60

A cloud security team is designing the management plane for a regulated workload on a public IaaS platform. They must ensure that administrative access to the cloud console and APIs is strongly controlled. Which TWO measures best satisfy this requirement? (Choose two.)

Hard
61

Which of the following is a key difference between a security group and a network ACL in a VPC?

Easy
62

A company uses Azure Functions for serverless data processing. To securely access an Azure SQL database, which of the following is the most secure method for managing the database connection string?

Medium
63

A startup is designing its first cloud landing zone and wants a guardrail that prevents any principal in the organization from disabling AWS CloudTrail logging in any account, including the management account, while still allowing normal administrative work. Which control achieves this with the LEAST operational overhead?

Easy
64

A cloud security team is designing network security for a multi-VPC architecture in AWS. Which TWO of the following are valid considerations for VPC peering?

Medium
65

A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?

Easy
66

A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?

Medium
67

A healthcare organization runs a regulated workload on a public cloud. The security team must ensure that data stored in object storage remains unreadable to the cloud provider's staff even if they have physical access to the storage media. Which approach best meets this requirement?

Medium
68

In a cloud environment using KVM, a security auditor wants to ensure that a tenant VM cannot access the memory of another tenant VM on the same physical host. Which resource isolation mechanism is specifically designed to prevent such memory access?

Hard
69

A cloud architect is designing VPC connectivity for a global organization with multiple AWS accounts. They need a central hub for connecting many VPCs together, supporting transitive routing. Which service should they use?

Hard
70

A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?

Medium
71

A cloud security architect is hardening the metadata service on a fleet of EC2 instances that host a customer-facing web application. The team wants to reduce the risk of server-side request forgery leading to credential theft, while keeping the application's legitimate ability to retrieve instance role credentials. Which TWO measures should the architect implement? (Choose two.)

Hard
72

A cloud security architect is designing a multi-tenant virtualized environment. Which type of hypervisor is considered most secure for cloud deployments due to its reduced attack surface and direct hardware control?

Easy
73

A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?

Medium
74

A cloud security engineer is configuring an Amazon S3 bucket that must store sensitive financial data. The requirement is that all data must be encrypted at rest with keys that the organization controls and can rotate, and that access to the keys must be auditable and separable from the data access permissions. Which S3 encryption option BEST meets these requirements?

Medium
75

A security analyst is configuring an API Gateway for a cloud application. The application must handle high traffic and prevent abuse from a single client. Which feature should the analyst enable to limit the number of requests from a client within a specified time window?

Medium
76

A cloud security engineer is hardening container runtime environments. Which TWO of the following are effective measures to prevent container escape?

Medium
77

A cloud security professional is concerned about VM escape attacks. Which mitigation is most effective?

Easy
78

An organization uses Azure Functions and needs to ensure that the function can securely access a database in a private VNet. What is the recommended approach?

Medium
79

A financial services company is migrating its cardholder data environment to a public cloud IaaS platform. The security team must determine which controls remain the customer's responsibility under the shared responsibility model. Which of the following is the customer's responsibility in this IaaS deployment?

Easy
80

A cloud architect is designing a multi-tenant environment. To ensure that a tenant's virtual machine cannot access another tenant's memory, which resource isolation technique should be enforced at the hypervisor level?

Hard
81

Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)

Easy
82

A healthcare company is migrating a legacy three-tier application to AWS. The security team must ensure that the database tier is reachable only from the application tier, that the rule follows the application instances automatically as they scale, and that no rule permits a broader source. Which mechanism should the team use?

Medium
83

During a security review of a serverless application, you notice that a Lambda function's execution role has permissions to delete all S3 buckets in the account. What is the most appropriate remediation to align with the principle of least privilege?

Hard
84

During a supply chain security review, a team discovers that container images are not being verified at admission time. Which Kubernetes-native tool should be implemented to ensure only signed images are deployed?

Hard
85

A cloud security team is reviewing container security practices. Which of the following is the most effective way to minimize the attack surface of a container image?

Easy
86

A cloud security architect is designing a workload that must store encryption keys in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. The workload runs on a major public cloud provider. The architect wants to minimize operational overhead while ensuring the keys never leave the HSM boundary. Which cloud service model should the architect select?

Medium
87

A cloud provider offers a virtual private cloud (VPC) with a subnet that hosts a database. A security architect must ensure that only instances in a specific application security group can connect to the database on port 3306, and that no other traffic from the internet or other subnets can reach it. The architect is configuring security groups and network ACLs. Which combination of rules BEST achieves this?

Hard
88

A cloud security administrator is responsible for managing access to a cloud management console. The organization wants to enforce multi-factor authentication (MFA) for all human users and ensure that programmatic access uses short-lived credentials instead of long-term access keys. Which approach BEST aligns with these requirements?

Easy
89

A cloud security team wants to enforce that only signed container images are deployed in their Kubernetes cluster. Which admission controller can validate image signatures at deploy time?

Hard
90

A cloud security team needs to ensure that an Amazon EC2 instance hosting a regulated workload cannot communicate with the public internet, but the instance must still be able to download OS patches from an internal repository and retrieve secrets from AWS Secrets Manager. The workload runs in a private subnet with no NAT gateway or internet gateway route. Which combination of configurations will meet these requirements with the LEAST operational overhead?

Medium
91

A cloud operations team runs a web tier on 40 Amazon EC2 instances behind an Application Load Balancer. Auditors require that administrators never hold long-lived SSH keys and that every login to an instance is logged with the identity of the human who initiated it. The team already uses an external SAML 2.0 identity provider for console access. Which approach BEST satisfies the auditors' requirements?

Medium
92

A financial services firm runs a regulated workload on a public cloud. Auditors require evidence that the cloud provider's physical security controls meet the firm's requirements. Which artifact provides the MOST direct evidence?

Hard
93

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to ensure that a compromised pod cannot reach the cloud provider's instance metadata service to steal node credentials. Which control BEST addresses this?

Hard
94

A security engineer is reviewing container security practices. Which tool is specifically designed to scan container images for Common Vulnerabilities and Exposures (CVEs)?

Easy
95

A company uses AWS and needs to allow a Lambda function in a VPC to access an S3 bucket without traversing the internet. Which solution meets this requirement securely?

Hard
96

During a security assessment of a Kubernetes cluster, you discover that a container is running as root with privileged mode enabled. Which of the following is the most critical risk associated with this configuration?

Hard
97

A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?

Hard
98

A cloud security professional is evaluating container runtime security. Which Linux capability should be dropped from a container to prevent it from loading kernel modules?

Easy
99

A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?

Easy
100

A security engineer is concerned about a scenario where a malicious process inside a VM breaks out of the virtualized environment to compromise the hypervisor. What is this attack called and what is the primary mitigation?

Medium
101

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application process cannot read another tenant's data. The architect plans to use AWS Key Management Service (KMS) with tenant-specific keys. Which of the following is the MOST critical security control to implement to achieve this isolation?

Medium
102

A healthcare cloud tenant must ensure that when a physical host is decommissioned, residual data in storage cannot be reconstructed. The provider offers self-encrypting drives. Which property most directly guarantees that cryptographic erasure is effective?

Hard
103

A security architect is designing a container runtime security strategy. Which of the following controls is most effective at preventing a container from compromising the host kernel?

Medium
104

A security architect is designing a VPC for a three-tier web application. Which of the following VPC subnet designs provides the most secure isolation for the database tier?

Medium
105

A financial services firm runs regulated workloads on Microsoft Azure. Auditors require that disk encryption keys for IaaS virtual machines remain under the firm's exclusive control, that the keys never leave a hardware security module, and that the firm can revoke access to the keys at any time, rendering the disks unreadable. The firm does not want Microsoft to be able to decrypt the disks without an explicit grant. Which Azure disk encryption configuration meets these requirements?

Hard
106

A cloud security auditor is reviewing container runtime configurations. Which TWO practices help prevent a container from compromising the host operating system?

Medium
107

A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?

Medium
108

A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?

Hard
109

A cloud security architect is designing a multi-tenant environment using Type 1 hypervisors. Which of the following is the primary security risk associated with this architecture?

Medium
110

A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which AWS network security component should they use?

Medium
111

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is logically isolated and that a compromised tenant cannot access another tenant's resources. The architect decides to use separate AWS accounts per tenant and wants to centralize security management. Which AWS service should be used to manage these accounts and apply security policies centrally?

Medium

Frequently asked questions

What does the Cloud Platform and Infrastructure Security domain cover on the CCSP exam?
You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.
How many questions are in this domain?
This page lists all 111 Cloud Platform and Infrastructure Security questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Platform and Infrastructure Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-ccsp ISC2-CCSP ccsp platform security Practice Questions