CCSP Cloud Platform and Infrastructure practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Cloud Platform and Infrastructure Security: 255 practice questions

CCSP 255 questions 12 shown free

12 of the 255 Cloud Platform and Infrastructure Security questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Remove unnecessary privileges and enforce runtime: Which control is most directly appropriate?

Hard
An online retailer’s incident review finds that a container ran with host-level privileges, allowing a compromised application process to reach host resources. The team proposes controls specifically addressing this demonstrated failure rather than estimating a new annual loss. Which control is most directly appropriate?
  1. Increase the vulnerability scanner’s reporting frequency.
    More reports may identify issues, but they do not remove excessive runtime privilege or strengthen host isolation.
  2. Remove unnecessary privileges and enforce runtime isolation with hardened host controls. ✓
    The demonstrated weakness is excessive container privilege and inadequate host isolation, requiring preventive runtime and host controls.
  3. Add a second container image scan after deployment without changing runtime configuration.
    Image scanning cannot establish host-kernel isolation or prevent privileged runtime behavior after deployment.
  4. Deploy a dashboard showing projected annual loss from container incidents.
    Risk quantification informs prioritization but does not directly correct the privilege and isolation failure.
The trap
Confuses image assurance with runtime containment. Improves discovery without correcting the exploited exposure. Substitutes measurement for the required technical control.

The failure involves excessive runtime privilege and weak host isolation, so controls must constrain both.

2. Correlated bastion records showing identity: Which evidence is most probative?

Hard
An insurance business requires every production administration session to enter through a bastion, use an identified user, satisfy its access policy, and be recorded. Auditors ask for evidence verifying this requirement for a sampled period. Which evidence is most probative?
  1. A network diagram showing the bastion between administrators and production systems.
    A diagram describes intended architecture but does not prove that sampled sessions followed it.
  2. Correlated bastion records showing identity, policy result, timing, target, and commands. ✓
    Correlated session records directly support the required path, identity, authorization, timing, destination, and recorded activity.
  3. A current bastion patch certificate.
    Patch evidence supports host maintenance but does not establish identity, authorization, routing, or session recording.
  4. A bastion inventory listing hosts and security groups.
    An inventory confirms deployed components but cannot verify that sampled sessions used the required path or controls.
The trap
Confuses host hygiene with access-path verification. Confuses asset presence with control operation. Confuses design documentation with operating evidence.

Correlated session records verify the required path, identity, authorization, target, and activity.

3. Revise dependency order: What remediation should the provider perform next?

Hard
A managed service provider’s recovery exercise met its data-loss objective but exceeded the contracted recovery-time objective because the application started before its identity, database, and network dependencies were restored. The exercise is complete, and production remains available. What remediation should the provider perform next?
  1. Revise dependency order, measure recovery time, and retest against the RTO. ✓
    The failed control concerns restoration order and elapsed recovery time, so the procedure must be corrected and measured through another test.
  2. Increase backup frequency to reduce recovery exposure.
    Backup frequency affects recoverable data loss, not the dependency sequence that caused the recovery-time delay.
  3. Add a standby region while leaving the restoration procedure unchanged.
    Another region does not correct the documented dependency-order failure or prove that recovery will meet the RTO.
  4. Tune application startup while leaving dependency restoration order unchanged.
    Changing startup behavior without restoring prerequisites in the required order leaves the identified recovery defect unresolved.
The trap
Confuses RPO remediation with RTO remediation. Assumes geographic redundancy fixes sequencing. Treats a symptom while preserving the failed procedure.

The failed objective is recovery time, so dependency ordering must be corrected and retested.

4. Separate management access and enforce identity-based: Which approach best addresses the stated constraint?

Hard
A logistics operator must protect administrative interfaces from workload traffic while keeping customer shipment processing online. The platform uses virtual machines, and the operator can create separate administrative paths without changing application flows. Which approach best addresses the stated constraint?
  1. Apply stricter workload firewall rules and leave management interfaces on the same path.
    Workload filtering does not provide the requested separation of administrative access from workload traffic.
  2. Separate management access and enforce identity-based administrative controls. ✓
    A distinct management path protects administration while preserving workload traffic, with identity and least privilege governing access.
  3. Move all virtual machines to containers so the provider manages their infrastructure boundary.
    Changing packaging does not inherently isolate management interfaces or remove customer control obligations.
  4. Encrypt customer traffic and assume administrative traffic is thereby separated.
    Encryption protects selected communication but does not create separate management-plane access or authorization boundaries.
The trap
Treats a platform change as automatic access isolation. Confuses confidentiality with plane separation. Confuses workload filtering with management-plane isolation.

Separate the management plane from workload traffic and apply identity-based, least-privilege administration.

5. The business service owner: Who is accountable for deciding whether to accept the correlated-site risk?

Medium
A media platform’s resilience review includes this evidence record: “Primary and recovery sites share one power utility and one upstream network carrier. Replication is asynchronous. The service owner has not approved residual-risk acceptance.” Engineering can propose alternatives, but business service ownership controls the continuity priority and risk decision. Who is accountable for deciding whether to accept the correlated-site risk?
  1. The incident response analyst who documented the review.
    The analyst records findings, while the designated service owner decides continuity priorities and residual-risk treatment.
  2. The facilities contractor managing site generators.
    Facilities can mitigate infrastructure dependencies but cannot accept the platform’s business continuity residual risk.
  3. The storage administrator operating asynchronous replication.
    Replication operators provide technical evidence but do not own correlated-site business impact or risk acceptance.
  4. The business service owner. ✓
    The service owner controls continuity priority and must accept or reject residual risk after engineering presents evidence and options.
The trap
Confuses component responsibility with enterprise accountability. Confuses assessment documentation with risk ownership. Confuses operational execution with accountable decision authority.

The business service owner decides whether correlated failure risk is acceptable after reviewing technical alternatives.

6. The designated accountable risk owner: Who should decide whether that residual risk is acceptable?

Hard
A distributed engineering team places workloads for several customers on shared cloud hosts. A review finds tenant-isolation controls exist, but residual cross-tenant exposure cannot be eliminated. Who should decide whether that residual risk is acceptable?
  1. The cloud platform operator, because that provider implements and operates the tenant-isolation controls.
    The operator may operate safeguards and provide evidence, but does not automatically own the customer’s residual-risk decision.
  2. The automated isolation monitor, because it continuously measures cross-tenant exposure and control status.
    A monitoring system supplies evidence but cannot independently accept an organizational risk or policy exception.
  3. The engineering team lead, because that person understands the isolation design and its operational limitations.
    The team lead may provide technical analysis, but technical involvement does not establish authority to accept residual organizational risk.
  4. The designated accountable risk owner. ✓
    The designated accountable owner decides whether the remaining risk fits organizational tolerance after considering evidence and business impact.
The trap
Assumes technical proximity grants risk-acceptance authority. Confuses control operation with risk accountability. Treats measurement as organizational accountability.

Residual-risk acceptance belongs to the designated accountable owner.

7. Enforce identity-aware workload policies with continuous: Which control best satisfies both requirements?

Easy
A public agency must prevent a compromised analytics workload from reaching unrelated services. Operations requires automated deployments, and access decisions must consider workload identity and current context rather than subnet location alone. Which control best satisfies both requirements?
  1. Enforce identity-aware workload policies with continuous context evaluation. ✓
    Identity-aware enforcement constrains workload traffic while reassessing context, satisfying both isolation and zero-trust requirements.
  2. Use static perimeter firewall rules.
    Static perimeter rules can filter traffic but do not reassess workload identity and context as required.
  3. Require multifactor authentication for every analytics administrator account.
    Multifactor authentication protects administrator access but does not constrain workload-to-workload communication.
  4. Place analytics workloads in one private subnet.
    A subnet organizes routing but does not itself provide workload-level isolation or contextual authorization.
The trap
Uses fixed location instead of dynamic trust evaluation. Confuses network placement with complete segmentation. Addresses human login rather than service communication.

Identity-aware workload enforcement limits lateral movement while supporting context-based decisions.

8. Verify configured replication and failover support: Select TWO actions that properly evaluate the request.

Medium
A telecommunications operator’s continuity policy permits an RPO exception only when the business impact analysis supports it and the named service authority approves it. A service requests a longer RPO because cross-region replication is costly. Select TWO actions that properly evaluate the request.

Select two. More than one option is correct — every correct one is ticked below.

  1. Verify configured replication and failover support the approved interval in testing. ✓
    Technical evidence must show that configured replication and failover can deliver the interval accepted under policy.
  2. Use measured RTO performance to set the permitted data-loss interval.
    RTO measures recovery time, while RPO defines the tolerable interval of data loss.
  3. Compare the requested loss interval with the service’s time-dependent business impact. ✓
    Business impact analysis determines whether the proposed data-loss interval is tolerable for the critical service.
  4. Treat cross-region replication as a tested, restorable backup.
    Replication may copy data across regions but does not by itself demonstrate restorable backup capability.
  5. Approve the exception based on the provider’s region count and availability claims.
    Region count and claims alone do not establish independent failure domains, complete replication, or successful failover.
The trap
Assumes geographic quantity proves resilience. Confuses replication with tested backup restoration. Confuses recovery time with recovery point.

Evaluate the business impact and verify configured recovery capability before approval.

9. Guest controls cannot verify the provider’s hypervisor: Which limitation specifically follows from this respon

Medium
A regional hospital group runs clinical applications on provider-managed virtual machines. The team hardens guests and scans images, but the contract grants no direct hypervisor or management-plane administration. Which limitation specifically follows from this responsibility boundary?
  1. No provider-side virtualization controls are relevant once guests are hardened.
    Provider-side hypervisor and management-plane controls remain relevant to platform security and tenant isolation.
  2. Guest controls cannot verify the provider’s hypervisor or management-plane security. ✓
    The customer controls guests and images, while the provider controls the underlying virtualization and management layers.
  3. Guest hardening proves the provider’s hypervisor configuration is secure.
    Guest controls protect the virtual machines but cannot verify the provider-managed hypervisor configuration.
  4. Image scanning establishes runtime tenant isolation across the provider platform.
    Image scanning evaluates packaged software and does not establish runtime isolation or management-plane security.
The trap
Treats guest evidence as platform evidence. Treats artifact evidence as runtime isolation evidence. Assumes guest hardening eliminates lower-layer responsibilities.

Guest and image controls cannot verify provider-managed hypervisor or management-plane security.

10. The paths do not provide independent failure domains: What conclusion should the engineering team record?

Medium
A software provider records that an application uses two network paths. Both paths terminate on the same upstream router, and a maintenance test disables that router and interrupts both paths. What conclusion should the engineering team record?
  1. The paths provide adequate redundancy because two endpoints are configured.
    Endpoint count does not establish separate power, routing, or infrastructure failure domains.
  2. The paths constitute a tested backup because traffic resumed afterward.
    Traffic recovery after restoration does not prove alternate-path operation during the router failure.
  3. The paths do not provide independent failure domains. ✓
    A shared upstream router is a common failure mechanism, so the paths are not independent for resilience.
  4. The paths are independent because they use different cables.
    Different cables do not eliminate dependence on the same upstream router or shared infrastructure.
The trap
Confuses restoration with failover. Mistakes physical diversity for failure-domain independence. Counts components instead of analyzing common dependencies.

A shared upstream router creates a common failure mechanism despite separate physical paths.

11. Obtain accountable owner acceptance: What should happen next?

Medium
A training company estimates annual loss before a tenancy control at $240,000 and after it at $90,000. The control costs $40,000 annually. The calculation is documented, but no accountable owner has accepted the remaining risk. What should happen next?
  1. Let the calculation tool approve the exception
    A calculation tool provides analysis, but organizational authority remains with the designated risk owner.
  2. Reject the control because its benefit is not zero
    Controls need not eliminate all loss; expected benefit and residual exposure inform an acceptance decision.
  3. Deploy the control and close the risk
    A control reduces expected loss but does not eliminate residual risk or replace formal acceptance.
  4. Obtain accountable owner acceptance ✓
    The remaining risk and uncertainty require acceptance by the designated accountable owner after reviewing the calculation.
The trap
Applies an impossible zero-risk threshold. Treats risk reduction as risk elimination. Confuses quantitative output with approval authority.

The accountable owner must review and accept the documented residual risk after control economics are known.

12. Terminate permitted TLS sessions at an authorized: Select TWO actions that address the visibility gap.

Medium
A university research consortium finds that encrypted research traffic bypasses its inspection gateway, although identity logs show successful authentication. Policy authorizes inspection of consortium-managed endpoints and services. Select TWO actions that address the visibility gap.

Select two. More than one option is correct — every correct one is ticked below.

  1. Terminate permitted TLS sessions at an authorized inspection point. ✓
    An authorized termination point can make permitted TLS payloads available for inspection without disabling transport protection generally.
  2. Replace payload inspection with DNS filtering for encrypted research flows.
    DNS filtering evaluates name-resolution activity and does not inspect encrypted application payloads.
  3. Collect endpoint or service telemetry for flows that remain encrypted. ✓
    Endpoint or service telemetry adds visibility when the gateway cannot terminate or inspect the encrypted flow.
  4. Treat successful authentication as sufficient evidence of safe traffic.
    Authentication records identity-related evidence but do not reveal encrypted payload behavior or prove that activity is safe.
  5. Disable TLS on research connections to expose their application payloads.
    Disabling TLS sacrifices transport protection when authorized termination or endpoint telemetry can provide visibility.
The trap
Confuses identity evidence with traffic inspection. Selects a control at the wrong inspection layer. Removes protection instead of addressing the inspection boundary.

Authorized TLS termination and endpoint or service telemetry address encrypted-traffic visibility gaps.

243 more Cloud Platform and Infrastructure Security questions

The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Cloud Platform and Infrastructure Security · Every answer, right and wrong, comes with its own explanation.