โ† All CCSK Flashcard Decks

Infrastructure Security and Virtualization Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Infrastructure Security and Virtualization flashcards as text
  1. What does CCSK recommend for securing Kubernetes API servers in cloud-hosted container environments?

    Answer: Restrict API server access using network policies, RBAC, and strong authentication

    The Kubernetes API server controls the entire cluster and must be protected with network restrictions, RBAC, mutual TLS, and strong authentication to prevent unauthorized cluster control.

  2. What is 'serverless security' and what unique attack surface does it introduce?

    Answer: Serverless shifts security to function-level permissions and input validation, introducing risks like event injection and over-privileged functions

    Serverless functions are triggered by events, introducing event injection risks, and often have overly broad permissions that must be minimized following least-privilege principles.

  3. According to CCSK, what is the primary security challenge of 'ephemeral computing' in cloud environments?

    Answer: Short-lived resources may not generate sufficient logs before termination, creating forensic and audit gaps

    Ephemeral resources may terminate before logs are collected, making incident investigation and compliance auditing difficult if centralized logging is not configured.

  4. What is 'cloud workload protection platform' (CWPP) and what does it protect?

    Answer: A security solution that provides visibility and protection for workloads across VMs, containers, and serverless functions

    CWPPs provide runtime security, vulnerability management, and threat detection for cloud workloads regardless of their form factor (VMs, containers, serverless).

  5. What does CCSK say about the use of 'bastion hosts' (jump servers) for cloud infrastructure access?

    Answer: Bastion hosts provide a controlled, audited, single entry point for administrative access to cloud infrastructure

    A bastion host channels all administrative access through a single hardened, monitored entry point, reducing attack surface and creating an audit trail.

  6. In CCSK infrastructure security, what is 'drift detection' and why is it important?

    Answer: Identifying when cloud infrastructure deviates from its approved baseline configuration

    Drift detection identifies when deployed infrastructure diverges from its approved IaC baseline, which may indicate unauthorized changes or compromise.