โ† All CCSP Flashcard Decks

Cloud Platform and Infrastructure Security Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Platform and Infrastructure Security flashcards as text
  1. What is the primary security concern with container escapes in a cloud environment?

    Answer: An attacker who escapes a container can potentially access the host OS and other containers

    A container escape vulnerability allows a process inside a container to break out to the host kernel, potentially compromising the entire host and co-located containers.

  2. Which approach best secures secrets (API keys, passwords) in a cloud-native application?

    Answer: Using a dedicated secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager)

    Dedicated secrets management services provide centralized, audited, and access-controlled storage for secrets, with automatic rotation capabilities.

  3. In cloud networking, what does microsegmentation achieve?

    Answer: Isolates individual workloads with granular policy controls, limiting lateral movement by attackers

    Microsegmentation creates fine-grained security zones around individual workloads, so that even if an attacker compromises one, lateral movement is severely restricted.

  4. What is the shared responsibility model's division regarding physical security of a public cloud data center?

    Answer: Entirely the cloud service provider's responsibility

    In all public cloud service models (IaaS, PaaS, SaaS), physical security of the data center infrastructure is always the cloud provider's responsibility.

  5. Which technique helps detect unauthorized changes to cloud infrastructure configurations?

    Answer: Continuous configuration monitoring and drift detection

    Continuous configuration monitoring compares the running infrastructure state against a known-good baseline to detect and alert on unauthorized changes (drift).

  6. What is the key security benefit of using a zero-trust network architecture in the cloud?

    Answer: It assumes no implicit trust for any user or device, requiring continuous verification regardless of network location

    Zero trust eliminates the concept of a trusted internal network, requiring identity verification and least-privilege access for every request, reducing breach impact.