Skip to content
ISC2 CCSP · CCSP

CCSP Domain 3: Cloud Platform and Infrastructure Security

Domain 3.0: Cloud Platform and Infrastructure Security · 17% of the exam

The platform your workloads sit on: all five objectives (3.1–3.5), from the infrastructure components and the management plane that creates and controls every one of them, through secure data center design and the redundancy notation that gets misquoted, risk identification, analysis and treatment, the selection and implementation of security controls, and business continuity and disaster recovery planning that is measured rather than assumed.

5 modules · 20 topics 87-page PDF 50 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$99one-time · all 6 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

17% of your exam score

Domain 3.0 is worth 17% of the CCSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CCSP objectives 3.1–3.5: 20 in-depth topics with worked scenarios and exam tips, in a 87-page guide you'll actually finish.

50 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cloud credential, freshly rewritten

CCSP is the vendor-neutral cloud security certification, and the outline effective 1 August 2026 is brand new, with two AI objectives no incumbent book on the shelf covers.

Serving, transitioning, or a military spouse?

CCSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 3.1, Cloud infrastructure components, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 3.1

Comprehend cloud infrastructure components

The physical environment, virtualization, network, storage and compute layers — and the management plane that creates and controls all of them.

Kofi Mensah ran infrastructure for Cobalt Grocery Group for eleven years before the migration, and had a mental model of the estate that was largely physical: nine racks in Warsaw, two uplinks, a SAN, a tape library, a locked door. Six months in, his mental model had one component in it that had never existed before, and that component was where he spent most of his attention.

“In Warsaw,” he told the risk committee, “if you wanted to build a hundred servers you needed a purchase order, a delivery, four engineers and a weekend. Here, one API call with the wrong credential does it in ninety seconds, from anywhere on earth. That API is the datacentre now.”

Exam focus · The management plane is the answer more often than you expect

When a scenario describes an attacker gaining broad, fast, estate-wide capability, or asks which component's compromise is most severe, or asks where to concentrate privileged access controls, the answer is the management plane. It is reachable over the internet by design, it is the only place where a single credential can affect everything, and unlike a physical datacentre it has no doors, guards or distance to slow an attacker down.

Physical environment

The buildings, power, cooling, cabling and physical security that everything else stands on. In public cloud this is entirely the provider's responsibility and entirely outside the customer's sight, which is why assurance here comes from attestation reports rather than from inspection. What the customer still owns: choosing a region, understanding what a region and an availability zone actually mean in that provider's terms, and knowing which facility-level failure modes the chosen architecture survives.

Two definitions worth being precise about, because scenarios rely on them. An availability zone is one or more discrete datacentres with independent power, cooling and networking within a region, close enough for low-latency synchronous replication. A region is a geographically separate set of availability zones, far enough apart that a regional disaster does not affect another region — and it is the boundary that data residency commitments are written against.

Virtualization

ElementFunction and security position
HypervisorPresents virtual hardware to guests and enforces isolation between them. Type 1 runs on bare metal; type 2 runs on a host operating system and inherits its attack surface. In public cloud this is provider-owned and increasingly offloaded to dedicated hardware, which shrinks the software surface substantially.
Guest virtual machinesCustomer-owned in IaaS: guest OS hardening, patching, agents and configuration. The provider does not patch your guests.
ContainersOS-level virtualization sharing the host kernel. Faster and denser than VMs, with a weaker isolation boundary. Multi-tenant container platforms usually place tenants in separate VMs underneath for this reason.
Virtual networking and storageVirtual switches, virtual NICs and virtual disks. Configuration is where tenant separation is expressed, which makes misconfiguration the practical risk rather than escape.
EscapeThe catastrophic case: a guest breaking out to the hypervisor or host and reaching other tenants. Rare, heavily researched, and mitigated by provider patching, hardware isolation and, for high-assurance workloads, dedicated hosts.
The guide continues for 87 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 50-question bank. Tap an answer for instant feedback and the explanation.

From module 3.1 · Cloud infrastructure components

  1. 1. Which cloud infrastructure component, if compromised, most directly grants control of the entire estate?

From module 3.2 · Designing a secure data center

  1. 1. A facility must allow any capacity component to be removed for planned maintenance without disrupting IT operations. Which Uptime Institute tier does this describe?

From module 3.3 · Analyzing infrastructure and platform risk

  1. 1. An asset worth €400,000 has an exposure factor of 0.25 for a given event, which is expected once every four years. What is the annualized loss expectancy?

47 more questions like these are waiting inside.

What's inside

  • 20 published sub-topics across 5 modules, mapped to objectives 3.1–3.5
  • 50 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • N+1, 2N and the Uptime Institute tiers, stated precisely
  • The SLE, ARO and ALE arithmetic, worked end to end
  • Complete CCSP acronym & key-term reference
  • 87-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 3.1

    Cloud infrastructure components

    Comprehend cloud infrastructure components

    10 Qs
    Management planeHypervisor & virtualization layerSoftware-defined networkingCompute modelsStorage tiersResponsibility by layer
  2. 3.2

    Designing a secure data center

    Design a secure data center

    10 Qs
    Tenant partitioningUptime Institute tiersN+1 vs 2N redundancyHot/cold aisle containmentMulti-vendor pathway diversityBuy vs build
  3. 3.3

    Analyzing infrastructure and platform risk

    Analyze risks associated with cloud infrastructure and platforms

    10 Qs
    Inherent vs residual riskQualitative vs quantitativeSLE, ARO, ALERisk treatment optionsConcentration riskRisk register & ownership
  4. 3.4

    Planning and implementing security controls

    Plan and implementation of security controls

    10 Qs
    Control functions & typesPreventive guardrailsIAAA sequenceAttribute-based access controlTraffic mirroringLog correlation
  5. 3.5

    Business continuity and disaster recovery

    Plan Business Continuity (BC) and Disaster Recovery (DR)

    10 Qs
    BC vs DRRTO / RPO / RSL / MTDCold, warm, hot, active-activeTabletop to full interruptionPilot light & warm standbyCloud failure scopes
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 6 CCSP domains

Sitting the whole exam? Get the Complete CCSP Collection.

Every domain of the exam, including this guide, for $99, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CCSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CCSP objectives (3.1–3.5), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 50 practice questions, plus a 87-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 3.0 (17% of the exam). To prepare for the whole exam, the Complete CCSP Collection bundles all 6 domains for $99, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 17% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide