ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A security architect is designing an on-premises OpenStack deployment. Corporate policy states that every compute host must validate the integrity of its BIOS, bootloader, and type-1 hypervisor at power-on, and must be able to prove its trusted state to the cloud controller before any tenant workloads are started. The team wants to use the cryptographic chip that is already soldered onto most enterprise server motherboards and avoid adding external devices. Which mechanism BEST satisfies these requirements?

  • Use self-encrypting drives (SEDs) that automatically wipe keys on reboot to prevent unauthorized boot tampering.

  • Deploy Network Access Control (NAC) using 802.1X to authenticate servers before they join the management VLAN.

  • Implement a Trusted Platform Module (TPM) on each host and enable secure/measured boot with remote attestation.

  • Install a dedicated Hardware Security Module (HSM) cluster to store encryption keys for the hypervisor.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot