Courseiva

CCSP · topic practice

Cloud Platform and Infrastructure Security practice questions

This domain covers securing cloud infrastructure: compute, containers, networking, and storage. It tests how you design isolation, identity, and network controls across IaaS and managed platforms, and how you harden Kubernetes, VPCs, and virtual machines against privilege escalation, breakout, and data exposure.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cloud Platform and Infrastructure Security

What the exam tests

What to know about Cloud Platform and Infrastructure Security

You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.

Kubernetes hardening: Pod Security Admission, securityContext, seccomp/AppArmor, read-only root filesystems, dropping Linux capabilities.

AWS network controls: security groups, NACLs, VPC endpoints, PrivateLink, NAT gateways, and route table isolation.

Compute isolation: EC2 tenancy, dedicated hosts, instance metadata service (IMDSv2), and hypervisor separation.

Storage and data protection: KMS encryption, S3 bucket policies, EBS snapshots, and key rotation.

Watch out for

Common Cloud Platform and Infrastructure Security exam traps

  • ▸Confusing security groups (stateful, instance-level allow rules) with NACLs (stateless, subnet-level allow/deny rules).
  • ▸Assuming Kubernetes NetworkPolicy alone isolates pods; it requires a CNI that enforces it and does not replace authentication.
  • ▸Forgetting that IMDSv1 is vulnerable to SSRF; IMDSv2 uses session tokens and should be enforced on EC2 instances.

Practice set

Cloud Platform and Infrastructure Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Study the full virtualization explanation →

A cloud provider uses KVM as its hypervisor. To prevent a malicious VM from reading memory allocated to another VM, which hardware-assisted memory isolation technology should be enabled?

An organization uses a multi-cloud strategy and wants to connect their on-premises data center to multiple cloud providers with a single private, low-latency connection. Which solution should they consider?

A security architect is designing a multi-tenant cloud environment. Which hypervisor type provides the strongest isolation between tenant virtual machines by running directly on the hardware without a host operating system?

In a cloud VPC design, which component acts as a stateful firewall at the instance level, allowing only inbound rules?

Question 5mediummultiple choice
Review the full routing breakdown →

A company has multiple virtual private clouds in the same region and wants to enable direct IP connectivity between them using private IP addresses. However, they do not need transitive routing across multiple VPCs. Which solution should they use?

Question 6mediummulti select
Review the full subnetting walkthrough →

An organization is designing a VPC with multiple tiers. Which TWO network components are used to restrict traffic between subnets?

Question 7mediummultiple choice
Review the full subnetting walkthrough →

A company uses serverless functions to process sensitive data. The functions need to access a database in a private subnet. What is the most secure way to enable this access without exposing the database to the internet?

A cloud security architect is designing network connectivity between multiple virtual networks in the same region. The requirement is to allow full mesh connectivity with centralized management and the ability to apply network policies. Which service should be used?

A cloud security team is implementing container runtime security. Which of the following measures is most effective at preventing a container from breaking out to the host OS?

A cloud security architect is evaluating options for private connectivity to cloud services without traversing the internet. Which TWO services can be used to achieve this? (Select two.)

In a Kubernetes cluster, a pod needs to access a cloud provider's key management service (KMS) to retrieve secrets. Which of the following RBAC configurations is the least privileged approach?

A company is using AWS Lambda functions that need to access a private RDS database. Which configuration allows the Lambda function to connect securely without traversing the internet?

A cloud architect is securing a serverless application that uses serverless functions and an API gateway. Which TWO practices help protect against injection attacks?

A cloud security professional is designing network security for a VPC hosting a three-tier application. The database tier must be isolated from direct internet access and only accessible from the application tier. Which TWO AWS services can be used together to achieve this?

A security auditor is reviewing a cloud provider's virtualisation infrastructure. Which TWO mechanisms ensure VM isolation at the hardware level to prevent one tenant from accessing another's resources?

A financial services company is deploying a new cloud-native application on AWS. The security team needs to ensure that all data stored in Amazon S3 is encrypted at rest using a key that the company controls and can rotate independently of the cloud provider. The company also requires an audit trail of every time the key is used to encrypt or decrypt data. Which AWS service should they use to meet these requirements?

A cloud security architect is designing a secure architecture for a multi-tier web application on Google Cloud. The application consists of a web tier, an application tier, and a database tier. The architect needs to implement network segmentation to limit lateral movement in case of a breach. Which TWO of the following Google Cloud features should be used to achieve micro-segmentation and enforce least privilege at the network layer? (Choose two.)

Question 18mediummulti select
Review the full subnetting walkthrough →

A cloud security engineer is reviewing the security configuration of an Amazon EC2 instance that hosts a web application. The instance is in a public subnet and must be accessible from the internet on ports 80 and 443. The engineer needs to ensure that the instance is protected from unauthorized access. Which TWO of the following are the MOST effective security controls to implement? (Choose two.)

A company is migrating its on-premises Oracle database to Oracle Cloud Infrastructure (OCI). The security team is concerned about protecting the data at rest and in transit. They want to ensure that the database is encrypted using keys managed by OCI, and that all connections to the database use TLS. Which OCI service should they use to manage the encryption keys?

A company is migrating a legacy application to Microsoft Azure. The application requires a fixed public IP address and must be protected from volumetric DDoS attacks. The security team also wants to ensure that only HTTP and HTTPS traffic reaches the application. Which Azure service should they use to meet these requirements?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Platform and Infrastructure Security sessions

Start a Cloud Platform and Infrastructure Security only practice session

Every question in these sessions is drawn from the Cloud Platform and Infrastructure Security domain — nothing else.

Related practice questions

Related CCSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCSP exam test about Cloud Platform and Infrastructure Security?
You must be able to select and configure the right isolation and hardening controls for compute, containers, and networks. The single most important thing is knowing which control applies at which layer—subnet, instance, pod, or identity—and what it actually enforces.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Platform and Infrastructure Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Platform and Infrastructure Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCSP topics?
Use the topic links above to move to related areas, or go back to the CCSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCSP exam covers. They are not copied from any real exam or dump site.