CCSP Cloud Platform and Infrastructure Security: 255 practice questions
12 of the 255 Cloud Platform and Infrastructure Security questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CCSP? Take the free 5-min readiness check →
1. Remove unnecessary privileges and enforce runtime: Which control is most directly appropriate?
- Increase the vulnerability scanner’s reporting frequency.More reports may identify issues, but they do not remove excessive runtime privilege or strengthen host isolation.
- Remove unnecessary privileges and enforce runtime isolation with hardened host controls. ✓The demonstrated weakness is excessive container privilege and inadequate host isolation, requiring preventive runtime and host controls.
- Add a second container image scan after deployment without changing runtime configuration.Image scanning cannot establish host-kernel isolation or prevent privileged runtime behavior after deployment.
- Deploy a dashboard showing projected annual loss from container incidents.Risk quantification informs prioritization but does not directly correct the privilege and isolation failure.
The failure involves excessive runtime privilege and weak host isolation, so controls must constrain both.
2. Correlated bastion records showing identity: Which evidence is most probative?
- A network diagram showing the bastion between administrators and production systems.A diagram describes intended architecture but does not prove that sampled sessions followed it.
- Correlated bastion records showing identity, policy result, timing, target, and commands. ✓Correlated session records directly support the required path, identity, authorization, timing, destination, and recorded activity.
- A current bastion patch certificate.Patch evidence supports host maintenance but does not establish identity, authorization, routing, or session recording.
- A bastion inventory listing hosts and security groups.An inventory confirms deployed components but cannot verify that sampled sessions used the required path or controls.
Correlated session records verify the required path, identity, authorization, target, and activity.
3. Revise dependency order: What remediation should the provider perform next?
- Revise dependency order, measure recovery time, and retest against the RTO. ✓The failed control concerns restoration order and elapsed recovery time, so the procedure must be corrected and measured through another test.
- Increase backup frequency to reduce recovery exposure.Backup frequency affects recoverable data loss, not the dependency sequence that caused the recovery-time delay.
- Add a standby region while leaving the restoration procedure unchanged.Another region does not correct the documented dependency-order failure or prove that recovery will meet the RTO.
- Tune application startup while leaving dependency restoration order unchanged.Changing startup behavior without restoring prerequisites in the required order leaves the identified recovery defect unresolved.
The failed objective is recovery time, so dependency ordering must be corrected and retested.
4. Separate management access and enforce identity-based: Which approach best addresses the stated constraint?
- Apply stricter workload firewall rules and leave management interfaces on the same path.Workload filtering does not provide the requested separation of administrative access from workload traffic.
- Separate management access and enforce identity-based administrative controls. ✓A distinct management path protects administration while preserving workload traffic, with identity and least privilege governing access.
- Move all virtual machines to containers so the provider manages their infrastructure boundary.Changing packaging does not inherently isolate management interfaces or remove customer control obligations.
- Encrypt customer traffic and assume administrative traffic is thereby separated.Encryption protects selected communication but does not create separate management-plane access or authorization boundaries.
Separate the management plane from workload traffic and apply identity-based, least-privilege administration.
5. The business service owner: Who is accountable for deciding whether to accept the correlated-site risk?
- The incident response analyst who documented the review.The analyst records findings, while the designated service owner decides continuity priorities and residual-risk treatment.
- The facilities contractor managing site generators.Facilities can mitigate infrastructure dependencies but cannot accept the platform’s business continuity residual risk.
- The storage administrator operating asynchronous replication.Replication operators provide technical evidence but do not own correlated-site business impact or risk acceptance.
- The business service owner. ✓The service owner controls continuity priority and must accept or reject residual risk after engineering presents evidence and options.
The business service owner decides whether correlated failure risk is acceptable after reviewing technical alternatives.
6. The designated accountable risk owner: Who should decide whether that residual risk is acceptable?
- The cloud platform operator, because that provider implements and operates the tenant-isolation controls.The operator may operate safeguards and provide evidence, but does not automatically own the customer’s residual-risk decision.
- The automated isolation monitor, because it continuously measures cross-tenant exposure and control status.A monitoring system supplies evidence but cannot independently accept an organizational risk or policy exception.
- The engineering team lead, because that person understands the isolation design and its operational limitations.The team lead may provide technical analysis, but technical involvement does not establish authority to accept residual organizational risk.
- The designated accountable risk owner. ✓The designated accountable owner decides whether the remaining risk fits organizational tolerance after considering evidence and business impact.
Residual-risk acceptance belongs to the designated accountable owner.
7. Enforce identity-aware workload policies with continuous: Which control best satisfies both requirements?
- Enforce identity-aware workload policies with continuous context evaluation. ✓Identity-aware enforcement constrains workload traffic while reassessing context, satisfying both isolation and zero-trust requirements.
- Use static perimeter firewall rules.Static perimeter rules can filter traffic but do not reassess workload identity and context as required.
- Require multifactor authentication for every analytics administrator account.Multifactor authentication protects administrator access but does not constrain workload-to-workload communication.
- Place analytics workloads in one private subnet.A subnet organizes routing but does not itself provide workload-level isolation or contextual authorization.
Identity-aware workload enforcement limits lateral movement while supporting context-based decisions.
8. Verify configured replication and failover support: Select TWO actions that properly evaluate the request.
Select two. More than one option is correct — every correct one is ticked below.
- Verify configured replication and failover support the approved interval in testing. ✓Technical evidence must show that configured replication and failover can deliver the interval accepted under policy.
- Use measured RTO performance to set the permitted data-loss interval.RTO measures recovery time, while RPO defines the tolerable interval of data loss.
- Compare the requested loss interval with the service’s time-dependent business impact. ✓Business impact analysis determines whether the proposed data-loss interval is tolerable for the critical service.
- Treat cross-region replication as a tested, restorable backup.Replication may copy data across regions but does not by itself demonstrate restorable backup capability.
- Approve the exception based on the provider’s region count and availability claims.Region count and claims alone do not establish independent failure domains, complete replication, or successful failover.
Evaluate the business impact and verify configured recovery capability before approval.
9. Guest controls cannot verify the provider’s hypervisor: Which limitation specifically follows from this respon
- No provider-side virtualization controls are relevant once guests are hardened.Provider-side hypervisor and management-plane controls remain relevant to platform security and tenant isolation.
- Guest controls cannot verify the provider’s hypervisor or management-plane security. ✓The customer controls guests and images, while the provider controls the underlying virtualization and management layers.
- Guest hardening proves the provider’s hypervisor configuration is secure.Guest controls protect the virtual machines but cannot verify the provider-managed hypervisor configuration.
- Image scanning establishes runtime tenant isolation across the provider platform.Image scanning evaluates packaged software and does not establish runtime isolation or management-plane security.
Guest and image controls cannot verify provider-managed hypervisor or management-plane security.
10. The paths do not provide independent failure domains: What conclusion should the engineering team record?
- The paths provide adequate redundancy because two endpoints are configured.Endpoint count does not establish separate power, routing, or infrastructure failure domains.
- The paths constitute a tested backup because traffic resumed afterward.Traffic recovery after restoration does not prove alternate-path operation during the router failure.
- The paths do not provide independent failure domains. ✓A shared upstream router is a common failure mechanism, so the paths are not independent for resilience.
- The paths are independent because they use different cables.Different cables do not eliminate dependence on the same upstream router or shared infrastructure.
A shared upstream router creates a common failure mechanism despite separate physical paths.
11. Obtain accountable owner acceptance: What should happen next?
- Let the calculation tool approve the exceptionA calculation tool provides analysis, but organizational authority remains with the designated risk owner.
- Reject the control because its benefit is not zeroControls need not eliminate all loss; expected benefit and residual exposure inform an acceptance decision.
- Deploy the control and close the riskA control reduces expected loss but does not eliminate residual risk or replace formal acceptance.
- Obtain accountable owner acceptance ✓The remaining risk and uncertainty require acceptance by the designated accountable owner after reviewing the calculation.
The accountable owner must review and accept the documented residual risk after control economics are known.
12. Terminate permitted TLS sessions at an authorized: Select TWO actions that address the visibility gap.
Select two. More than one option is correct — every correct one is ticked below.
- Terminate permitted TLS sessions at an authorized inspection point. ✓An authorized termination point can make permitted TLS payloads available for inspection without disabling transport protection generally.
- Replace payload inspection with DNS filtering for encrypted research flows.DNS filtering evaluates name-resolution activity and does not inspect encrypted application payloads.
- Collect endpoint or service telemetry for flows that remain encrypted. ✓Endpoint or service telemetry adds visibility when the gateway cannot terminate or inspect the encrypted flow.
- Treat successful authentication as sufficient evidence of safe traffic.Authentication records identity-related evidence but do not reveal encrypted payload behavior or prove that activity is safe.
- Disable TLS on research connections to expose their application payloads.Disabling TLS sacrifices transport protection when authorized termination or endpoint telemetry can provide visibility.
Authorized TLS termination and endpoint or service telemetry address encrypted-traffic visibility gaps.
243 more Cloud Platform and Infrastructure Security questions
The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CCSP readiness — freeOther CCSP domains
- Cloud Data Security — 300 questions →
- Cloud Concepts, Architecture and Design — 255 questions →
- Cloud Security Operations — 255 questions →
- Cloud Application Security — 240 questions →
- Legal, Risk and Compliance — 195 questions →
- All 1500 CCSP questions →
- CCSP certification: requirements, cost and exam format →