CCSP Domain 5: Cloud Security Operations
Domain 5.0: Cloud Security Operations · 17% of the exam
Running it, every day: all six objectives (5.1–5.6), from building the physical and logical infrastructure and operating it safely, through the twelve service management processes and the standards behind them, digital forensics when the media belongs to somebody else, communication with regulators, customers and providers, and the security operations that hold it all together.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
17% of your exam score
Domain 5.0 is worth 17% of the CCSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CCSP objectives 5.1–5.6: 42 in-depth topics with worked scenarios and exam tips, in a 103-page guide you'll actually finish.
60 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cloud credential, freshly rewritten
CCSP is the vendor-neutral cloud security certification, and the outline effective 1 August 2026 is brand new, with two AI objectives no incumbent book on the shelf covers.
Serving, transitioning, or a military spouse?
CCSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 5.1, Building cloud infrastructure, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Build and implement physical and logical infrastructure for cloud environment
Hardware roots of trust, secure defaults, standing up the management plane, virtual hardware configuration, and the guest toolsets that bridge guest and host.
Priya Raghunathan inherited Cobalt Grocery Group's cloud operations at the point where the migration stopped being a project and became a thing that had to run at three in the morning. Her first review question to the platform team was deliberately narrow: if we deployed a brand new account today and nobody configured anything, what would be true of it?
The answer was: storage unencrypted, public access permitted, all regions enabled, no logging, root user with a password and no MFA, and a default network with an internet gateway attached. Every one of those was a decision the platform had made on Cobalt's behalf, and every one of them was the wrong default for a grocery retailer holding 31 million loyalty records.
The examinable claim: a securely built platform is one where the unconfigured state is safe and someone must take a deliberate, logged, approved action to weaken it. That is achieved at build time through organization-level policy, hardened baseline templates and a landing zone, not through remediation afterwards. When a question offers “scan and fix non-compliant resources” against “prevent non-compliant resources being created”, the preventive option is the stronger answer.
Hardware-specific security configuration
| Device | What it is | What it is for |
|---|---|---|
| TPM | A Trusted Platform Module: a passive cryptographic chip bound to one machine, holding keys that cannot be exported and platform configuration registers that record measurements taken during boot. | Measured and secure boot, remote attestation of platform state, sealing keys so they release only when the platform measures as expected, and disk encryption keys bound to the machine. Per-host, low throughput. |
| HSM | A Hardware Security Module: a dedicated, tamper-resistant and tamper-responsive appliance that generates, stores and uses keys, validated against FIPS 140-2 or 140-3 at Levels 1 to 4. | High-volume cryptographic operations for many clients, certificate authority root keys, payment processing, and hold-your-own-key architectures. Keys never leave in plaintext. |
| Secure enclave / TEE | A hardware-isolated execution environment within the CPU. | Confidential computing: protecting data and code in use from the host operating system, the hypervisor and the platform operator. |
| Secure boot chain | UEFI Secure Boot verifying signatures on firmware and bootloader, extended by measured boot recording hashes into the TPM. | Preventing and detecting bootkits and unauthorized firmware. The foundation everything above it assumes. |
In public cloud, the equivalents are provider services — a managed HSM or key management service, virtual TPMs offered to instances, shielded or confidential VM types, and firmware integrity managed by the provider. The design question is the same: where is the root of trust, and who can reach it.
Secure by default
A build is secure by default when these are true before anyone configures anything.
- Encryption on for storage and databases at creation, with customer-managed keys enforced by policy for classified data.
- Public access denied at the organization level, so a resource-level policy cannot re-enable it.
- Deny-by-default networking, inbound and outbound, with no default network and no automatically attached internet gateway.
- No default or shared credentials; root or global administrator secured with a hardware key, credentials removed from routine use, and its use alarmed.
- Logging enabled in every account and every region, delivered to a separate logging account with immutability.
- Unused regions and services disabled, shrinking the surface an attacker can operate in unobserved.
- Minimal images — no build tools, no sample content, no unnecessary agents, no interactive access in production.
- Guardrails that constrain administrators, expressed as organization or service-control policies, so even a compromised account administrator cannot disable logging or open public access.
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.
From module 5.1 · Building cloud infrastructure
1. Which device is bound to a single machine, records boot measurements and can seal keys so they release only when the platform measures as expected?
From module 5.2 · Operating and maintaining cloud infrastructure
1. Which mechanism restarts guests on surviving hosts after an unplanned host failure, accepting some downtime?
From module 5.3 · Operational controls and standards
1. The same outage occurs three weeks running and is resolved each time by restarting a service. Which process should be invoked?
57 more questions like these are waiting inside.
What's inside
- 42 published sub-topics across 6 modules, mapped to objectives 5.1–5.6
- 60 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Isolate, never terminate: cloud forensics in the right order
- Incident versus problem, and change versus release versus deployment
- Complete CCSP acronym & key-term reference
- 103-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 5.110 Qs
Building cloud infrastructure
Build and implement physical and logical infrastructure for cloud environment
TPM vs HSMSecure by defaultHypervisor type 1 vs 2Guest virtualization toolsetsMemory overcommit & page sharingLanding zone - 5.210 Qs
Operating and maintaining cloud infrastructure
Operate and maintain physical and logical infrastructure for cloud environment
Bastion & session brokeringPatch by replacementLive migration vs HA restartMaintenance modeBaseline drift remediationBackup and restore testing - 5.310 Qs
Operational controls and standards
Implement operational controls and standards
Incident vs problemChange, release, deploymentConfiguration management databaseISO/IEC 20000-1COBIT vs COSOCIS Controls - 5.410 Qs
Supporting digital forensics
Support digital forensics
Order of volatilityIsolate vs terminateSnapshot & hashChain of custodyISO/IEC 27037Forensic readiness - 5.510 Qs
Communication with relevant parties
Manage communication with relevant parties
72-hour GDPR notificationController vs processor dutiesOut-of-band contactsSingle spokespersonProvider notification SLAStakeholder matrix - 5.610 Qs
Managing security operations
Manage security operations
SOC operating modelsMITRE ATT&CK coverageIR lifecycleShort vs long-term containmentVA vs pen test vs red teamMTTD / MTTR / dwell time

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CCSP Collection.
Every domain of the exam, including this guide, for $99, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CCSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CCSP objectives (5.1–5.6), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 60 practice questions, plus a 103-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 5.0 (17% of the exam). To prepare for the whole exam, the Complete CCSP Collection bundles all 6 domains for $99, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 17% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide