TechNuggets Academy

Cloud Platform and Infrastructure Security

Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Cloud Platform and Infrastructure Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Cloud Platform and Infrastructure Security
A cloud provider hosts multiple tenant VMs on a single physical host running a bare-metal (Type 1) hypervisor. A researcher discovers a flaw that lets a malicious VM break out of its isolation boundary and gain direct code execution on the hypervisor itself, from which other tenants' VMs on the same host could then be reached. What is this class of attack most precisely called?
VM escape refers specifically to breaking out of a guest VM's isolation to gain access to the underlying hypervisor/host. Guest hopping is the follow-on step of pivoting from the compromised hypervisor to another guest, but the vulnerability described (escaping to the hypervisor) is the VM escape itself.
Question 2 of 6 · Cloud Platform and Infrastructure Security
A company requires an RTO of 4 hours and an RPO of 15 minutes for its cloud-hosted ERP system while minimizing standby infrastructure cost. The database must replicate continuously to the recovery region, but application servers only need to be provisioned after a disaster is formally declared. Which BCDR strategy BEST meets these requirements?
Pilot light keeps only the critical core (here, the database) continuously replicated to satisfy the tight RPO, while non-core components (app servers) are scaled up from a minimal or dormant state only after failover is declared — matching the stated RTO of hours at minimal standing cost.
Question 3 of 6 · Cloud Platform and Infrastructure Security
A cloud provider states that its primary data center facility has N+1 redundant capacity components and multiple independent distribution paths for power and cooling, allowing planned maintenance to be performed without taking systems offline. However, the provider acknowledges that a single unplanned equipment failure could still cause a service outage. Per the Uptime Institute tiering system, which tier does this facility match?
Tier III facilities are 'concurrently maintainable' — they have redundant distribution paths and components so planned maintenance causes no downtime — but they are not required to be fault tolerant against a single unplanned failure, which is exactly what's described.
Question 4 of 6 · Cloud Platform and Infrastructure Security
A cloud security architect is hardening the virtual network fabric of a multi-tenant IaaS environment to prevent VLAN hopping attacks that rely on switch spoofing (an attacking host mimicking a trunking switch to negotiate a trunk link). Which configuration change directly closes this attack vector?
Switch-spoofing VLAN hopping exploits automatic trunk negotiation protocols like DTP. Disabling DTP and explicitly configuring which ports are trunks (with all other ports fixed as access ports) removes the attacker's ability to negotiate an unauthorized trunk link.
Question 5 of 6 · Cloud Platform and Infrastructure Security
A cloud customer needs to permanently retire a block storage volume in a multi-tenant public cloud environment where physical access to the underlying storage media is not possible. Which technique renders the volume's data unrecoverable without requiring physical destruction or block-level overwrite of the underlying media?
Crypto-shredding destroys the keys protecting encrypted data, making the ciphertext permanently unrecoverable without needing access to the physical media — the recommended sanitization method in cloud/multi-tenant environments where the customer cannot physically overwrite or destroy the underlying disks.
Question 6 of 6 · Cloud Platform and Infrastructure Security
A cloud security team discovers that management-console API keys with full administrative scope are hardcoded into CI/CD pipeline scripts stored in a shared repository accessible to every developer, allowing any developer — regardless of role — to make unrestricted changes to production cloud infrastructure. Which control BEST addresses this cloud management plane risk?
The core problem is excessive, shared, administrative-level privilege on the management plane. Replacing broadly-scoped shared keys with least-privilege, pipeline-specific IAM roles/credentials directly eliminates the overprivileged access rather than just obscuring or protecting the existing overprivileged keys.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →