โ† All CCSP Flashcard Decks

Cloud Platform and Infrastructure Security Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Platform and Infrastructure Security flashcards as text
  1. What is the purpose of a bastion host (jump server) in cloud infrastructure security?

    Answer: To provide a hardened, monitored single entry point for administrative access to private network resources

    A bastion host is a specially secured server that serves as the sole access point for SSH/RDP into private cloud networks, reducing the attack surface.

  2. Which cloud service model places the MOST infrastructure security responsibility on the cloud customer?

    Answer: Infrastructure as a Service (IaaS)

    In IaaS, the customer manages the OS, middleware, runtime, and applications, making them responsible for the largest share of security controls.

  3. What is a security group in AWS cloud infrastructure?

    Answer: A virtual stateful firewall that controls inbound and outbound traffic for cloud instances

    AWS Security Groups act as virtual stateful firewalls at the instance level, allowing administrators to define traffic rules based on port, protocol, and source/destination.

  4. What does the principle of immutable infrastructure mean in cloud security?

    Answer: Servers are never modified after deployment; changes are made by replacing instances with new ones

    Immutable infrastructure replaces running instances rather than patching them in place, reducing configuration drift and ensuring a known-good state.

  5. Which attack targets the management plane of a cloud environment to gain control over provisioning and configuration?

    Answer: Cloud management plane attack / API abuse

    The cloud management plane (control plane) is a high-value attack target because compromise of the API or console gives an attacker control over all cloud resources.

  6. What is the main purpose of a Cloud Access Security Broker (CASB)?

    Answer: To act as an intermediary that enforces security policies between cloud users and cloud services

    A CASB sits between cloud service consumers and providers to enforce visibility, compliance, data security, and threat protection policies.