CCSP Domain 3: Cloud Platform and Infrastructure Security
Domain 3.0: Cloud Platform and Infrastructure Security · 17% of the exam
The platform your workloads sit on: all five objectives (3.1–3.5), from the infrastructure components and the management plane that creates and controls every one of them, through secure data center design and the redundancy notation that gets misquoted, risk identification, analysis and treatment, the selection and implementation of security controls, and business continuity and disaster recovery planning that is measured rather than assumed.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
17% of your exam score
Domain 3.0 is worth 17% of the CCSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CCSP objectives 3.1–3.5: 20 in-depth topics with worked scenarios and exam tips, in a 87-page guide you'll actually finish.
50 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cloud credential, freshly rewritten
CCSP is the vendor-neutral cloud security certification, and the outline effective 1 August 2026 is brand new, with two AI objectives no incumbent book on the shelf covers.
Serving, transitioning, or a military spouse?
CCSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 3.1, Cloud infrastructure components, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Comprehend cloud infrastructure components
The physical environment, virtualization, network, storage and compute layers — and the management plane that creates and controls all of them.
Kofi Mensah ran infrastructure for Cobalt Grocery Group for eleven years before the migration, and had a mental model of the estate that was largely physical: nine racks in Warsaw, two uplinks, a SAN, a tape library, a locked door. Six months in, his mental model had one component in it that had never existed before, and that component was where he spent most of his attention.
“In Warsaw,” he told the risk committee, “if you wanted to build a hundred servers you needed a purchase order, a delivery, four engineers and a weekend. Here, one API call with the wrong credential does it in ninety seconds, from anywhere on earth. That API is the datacentre now.”
When a scenario describes an attacker gaining broad, fast, estate-wide capability, or asks which component's compromise is most severe, or asks where to concentrate privileged access controls, the answer is the management plane. It is reachable over the internet by design, it is the only place where a single credential can affect everything, and unlike a physical datacentre it has no doors, guards or distance to slow an attacker down.
Physical environment
The buildings, power, cooling, cabling and physical security that everything else stands on. In public cloud this is entirely the provider's responsibility and entirely outside the customer's sight, which is why assurance here comes from attestation reports rather than from inspection. What the customer still owns: choosing a region, understanding what a region and an availability zone actually mean in that provider's terms, and knowing which facility-level failure modes the chosen architecture survives.
Two definitions worth being precise about, because scenarios rely on them. An availability zone is one or more discrete datacentres with independent power, cooling and networking within a region, close enough for low-latency synchronous replication. A region is a geographically separate set of availability zones, far enough apart that a regional disaster does not affect another region — and it is the boundary that data residency commitments are written against.
Virtualization
| Element | Function and security position |
|---|---|
| Hypervisor | Presents virtual hardware to guests and enforces isolation between them. Type 1 runs on bare metal; type 2 runs on a host operating system and inherits its attack surface. In public cloud this is provider-owned and increasingly offloaded to dedicated hardware, which shrinks the software surface substantially. |
| Guest virtual machines | Customer-owned in IaaS: guest OS hardening, patching, agents and configuration. The provider does not patch your guests. |
| Containers | OS-level virtualization sharing the host kernel. Faster and denser than VMs, with a weaker isolation boundary. Multi-tenant container platforms usually place tenants in separate VMs underneath for this reason. |
| Virtual networking and storage | Virtual switches, virtual NICs and virtual disks. Configuration is where tenant separation is expressed, which makes misconfiguration the practical risk rather than escape. |
| Escape | The catastrophic case: a guest breaking out to the hypervisor or host and reaching other tenants. Rare, heavily researched, and mitigated by provider patching, hardware isolation and, for high-assurance workloads, dedicated hosts. |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 50-question bank. Tap an answer for instant feedback and the explanation.
From module 3.1 · Cloud infrastructure components
1. Which cloud infrastructure component, if compromised, most directly grants control of the entire estate?
From module 3.2 · Designing a secure data center
1. A facility must allow any capacity component to be removed for planned maintenance without disrupting IT operations. Which Uptime Institute tier does this describe?
From module 3.3 · Analyzing infrastructure and platform risk
1. An asset worth €400,000 has an exposure factor of 0.25 for a given event, which is expected once every four years. What is the annualized loss expectancy?
47 more questions like these are waiting inside.
What's inside
- 20 published sub-topics across 5 modules, mapped to objectives 3.1–3.5
- 50 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- N+1, 2N and the Uptime Institute tiers, stated precisely
- The SLE, ARO and ALE arithmetic, worked end to end
- Complete CCSP acronym & key-term reference
- 87-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 3.110 Qs
Cloud infrastructure components
Comprehend cloud infrastructure components
Management planeHypervisor & virtualization layerSoftware-defined networkingCompute modelsStorage tiersResponsibility by layer - 3.210 Qs
Designing a secure data center
Design a secure data center
Tenant partitioningUptime Institute tiersN+1 vs 2N redundancyHot/cold aisle containmentMulti-vendor pathway diversityBuy vs build - 3.310 Qs
Analyzing infrastructure and platform risk
Analyze risks associated with cloud infrastructure and platforms
Inherent vs residual riskQualitative vs quantitativeSLE, ARO, ALERisk treatment optionsConcentration riskRisk register & ownership - 3.410 Qs
Planning and implementing security controls
Plan and implementation of security controls
Control functions & typesPreventive guardrailsIAAA sequenceAttribute-based access controlTraffic mirroringLog correlation - 3.510 Qs
Business continuity and disaster recovery
Plan Business Continuity (BC) and Disaster Recovery (DR)
BC vs DRRTO / RPO / RSL / MTDCold, warm, hot, active-activeTabletop to full interruptionPilot light & warm standbyCloud failure scopes

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CCSP Collection.
Every domain of the exam, including this guide, for $99, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CCSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CCSP objectives (3.1–3.5), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 50 practice questions, plus a 87-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 3.0 (17% of the exam). To prepare for the whole exam, the Complete CCSP Collection bundles all 6 domains for $99, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 17% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide