ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A cloud provider is designing a multi-tenant DevOps PaaS that lets customers upload and run arbitrary build scripts during their CI/CD pipelines. The security team requires strong isolation so a compromised build job cannot read host files or affect other tenants, while operations staff need the solution to start in milliseconds and support thousands of concurrent jobs per host with minimal resource overhead. Which sandboxing technique best satisfies both isolation and performance requirements in this scenario?

  • Operating-system level containers that use Linux namespaces and cgroups

  • Traditional chroot jails inside the host operating system

  • Full virtual machines deployed on a bare-metal Type-1 hypervisor

  • Host-based application whitelisting enforced through a mandatory access control policy

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot