โ† All CCSK Flashcard Decks

Infrastructure Security and Virtualization Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Infrastructure Security and Virtualization flashcards as text
  1. What does CCSK say about the security of container images pulled from public registries?

    Answer: Container images from public registries should be scanned for vulnerabilities and malware before use in production

    Public container images may contain vulnerabilities or malicious code and must be scanned and validated before being deployed in production environments.

  2. What is 'container breakout' and how does it compare to hypervisor escape?

    Answer: Container breakout exploits vulnerabilities to escape the container to the host OS; it is more likely than hypervisor escape because containers share the host kernel

    Containers share the host kernel, making breakout more feasible than hypervisor escape; a kernel vulnerability can be exploited to gain host-level access.

  3. According to CCSK, what is 'infrastructure as code' (IaC) security scanning used to detect?

    Answer: Security misconfigurations and policy violations in infrastructure templates before deployment

    IaC security scanning analyzes templates like Terraform or CloudFormation for misconfigurations, overly permissive policies, or compliance violations before they are deployed.

  4. What is a 'software-defined network' (SDN) and what security advantage does it provide in cloud environments?

    Answer: A network whose control plane is software-based, enabling dynamic, programmable security policy enforcement

    SDN separates the control plane from the data plane, allowing security policies to be applied programmatically and dynamically across the virtual network.

  5. According to CCSK, what is the recommended approach to patch management for cloud-hosted workloads?

    Answer: Establish automated patching pipelines and replace rather than patch long-running instances when possible

    Automated patching and replacing instances with updated golden images is more reliable than manual patching and reduces the window of exposure.

  6. What is the security purpose of 'host-based intrusion detection systems' (HIDS) in cloud VMs?

    Answer: To detect unauthorized changes, malicious activity, or policy violations occurring within individual VMs

    HIDS monitors file integrity, system calls, and logs within individual VMs to detect compromise indicators that network-level monitoring cannot see.