Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.
Start practicing
Cloud Concepts, Architecture, and Design — choose a session length
Free · No account required
Domain overview
This domain covers cloud reference architecture, deployment and service models, security design principles, and shared responsibility. It is tested through scenario questions on hybrid/multi-cloud, portability, provider assurance reports like SOC 2 Type II, and SLA availability and financial impact calculations.
Exam objectives
Shared responsibility across IaaS, PaaS, and SaaS and cloud deployment models
Cloud reference architecture components: BCDR, virtualization, and network security
Provider assurance artifacts such as SOC 2 Type II and ISO/IEC 27001
SLA availability math, downtime, and vendor lock-in mitigation strategies
Assuming the provider secures everything; shared responsibility varies by service model and leaves customer duties.
Confusing SOC 2 Type II (operating effectiveness over time) with Type I (design at a point in time).
Treating 99.99% and 99.9% as similar; small percentage differences create large downtime and financial exposure.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?
2Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?
3A security auditor is reviewing a cloud provider's controls to ensure that customer data is appropriately isolated. Which design principle is most directly related to this requirement?
4A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?
5Which cloud characteristic allows a consumer to automatically provision computing resources, such as server time and storage, as needed without requiring human interaction with the service provider?
6A cloud customer is evaluating a provider's service level agreement (SLA) that guarantees 99.99% availability. What is the maximum allowable downtime per year (in minutes) before the SLA is violated?
7Which of the following is a key benefit of using containers, such as Docker, in a cloud environment to achieve portability?
8In the NIST SP 800-145 definition of cloud computing, which characteristic is described as the capability to rapidly and elastically provision and release resources, often automatically?
9A company wants to avoid vendor lock-in when adopting cloud services. Which strategy is most effective for achieving portability?
10In a public cloud IaaS environment, which of the following is the customer responsible for securing, according to the shared responsibility model?
11A community cloud is best suited for which scenario?
12Which audit report provides the most comprehensive assurance regarding a cloud provider's controls over a period of time, including controls related to security, availability, processing integrity, confidentiality, and privacy?
13A cloud security architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms should be implemented to prevent data leakage between tenants?
14An organization is migrating a legacy application to the cloud and wants to maximize elasticity. Which THREE characteristics should the application support to benefit from cloud elasticity?
15A company is considering moving its customer relationship management (CRM) system to the cloud. The CRM is accessed through a web browser and the provider handles all maintenance, security, and infrastructure. Which cloud service model is being used?
16Which cloud characteristic allows a user to automatically provision computing resources without requiring human interaction with the service provider?
17An organization wants to deploy a cloud environment where multiple separate agencies with common compliance requirements share the infrastructure, but each agency retains some control over their own resources. Which deployment model best fits this scenario?
18In a public cloud IaaS model, which of the following security controls is the cloud customer primarily responsible for implementing?
19A company is designing a multi-cloud strategy to avoid vendor lock-in and ensure portability. They are considering using containers and an open-source orchestration platform. Which of the following is the BEST choice to achieve workload portability across different cloud providers?
20An organization needs to migrate a legacy application to the cloud. The application requires full control over the operating system, middleware, and runtime. The team wants to minimize management overhead while retaining OS-level access. Which cloud service model is most appropriate?
21Which of the following is a key benefit of using a hybrid cloud deployment model?
22Which NIST-defined cloud characteristic ensures that resources can be scaled up and down rapidly based on demand?
23A cloud security architect is evaluating a CSP for a financial services client. Which of the following audit reports would provide the most comprehensive assurance regarding the CSP's controls over security, availability, processing integrity, confidentiality, and privacy?
24Which design principle is MOST directly concerned with the ability to move workloads between cloud providers or back on-premises without significant re-architecture?
25A company plans to deploy a multi-tier application across multiple cloud providers to avoid single points of failure. They need to ensure consistent security policies, including identity federation and network segmentation, across all environments. Which architecture consideration is MOST critical?
26A cloud architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms are essential to prevent tenant data leakage? (Choose two.)
27An organization is evaluating a cloud service provider and reviewing their SLA. Which THREE metrics are most important for assessing the provider's reliability and accountability? (Choose three.)
28A company is adopting a hybrid cloud strategy. Which TWO security considerations are most critical for maintaining a consistent security posture across environments? (Choose two.)
29A company wants to migrate its customer relationship management (CRM) system to the cloud and requires that the provider manages the underlying infrastructure, operating system, and middleware, while the company manages only the application and data. Which cloud service model best meets these requirements?
30A financial institution is subject to strict regulatory requirements that mandate data residency and physical control over its infrastructure. At the same time, it wants to leverage cloud bursting for peak loads. Which deployment model should the institution adopt?
31An organization is evaluating a cloud provider's SLA for a critical application. The provider offers a 99.95% uptime SLA with a 10% service credit for each 30-minute downtime period exceeding the threshold. The organization's business impact analysis requires a maximum downtime of 4.38 hours per year. Does the provider's SLA meet this requirement, and what is the annual allowed downtime based on the SLA?
32Which characteristic of cloud computing allows a user to provision computing resources automatically without requiring human interaction with the service provider?
33A cloud service provider (CSP) offers a shared infrastructure where multiple customers' virtual machines run on the same physical host but are isolated by the hypervisor. Which cloud deployment model does this represent?
34An organization is migrating a legacy application to the cloud and wants to minimize vendor lock-in. They plan to use containers orchestrated by Kubernetes. Which design principle is the organization primarily applying?
35Which of the following is a key consideration when evaluating a cloud service provider's ability to meet compliance requirements for data sovereignty?
36In the shared responsibility model for public cloud, which of the following is typically the responsibility of the cloud customer when using IaaS?
37A cloud architect is designing a solution that must automatically scale compute resources based on real-time demand. The application is stateless and can tolerate brief interruptions. Which cloud design principle is most directly addressed by this requirement?
38A company is migrating to a hybrid cloud and needs to ensure consistent security policies across both on-premises and cloud environments. Which of the following is the MOST critical consideration?
39Which NIST SP 800-145 cloud service model provides the consumer with the ability to deploy applications onto a cloud infrastructure where the consumer does not manage the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment?
40An organization is looking for a cloud deployment model that is provisioned for exclusive use by a single organization, but may be owned, managed, and operated by the organization, a third party, or some combination. Which deployment model is this?
41A cloud security architect is designing a multi-tenant SaaS application that must ensure strong isolation between tenants. Which TWO mechanisms are most effective for achieving multitenancy isolation?
42A company is evaluating cloud providers for a critical workload and requires high availability, disaster recovery, and portability. Which THREE factors should the company prioritize in the provider evaluation?
43Which cloud service model provides the customer with the most control over the underlying infrastructure, including operating systems and applications?
44A financial services company is required to keep customer data within a specific geographic boundary due to regulatory requirements. The company is evaluating cloud deployment models. Which model would best ensure data sovereignty while still providing scalability?
45A cloud provider's SLA guarantees 99.95% uptime for a service. Over a one-year period (365 days), what is the maximum allowed downtime in minutes to meet this SLA?
46Which characteristic of cloud computing allows a user to provision resources automatically without requiring human interaction with the service provider?
47An organization is moving a legacy application to the cloud and wants to minimize changes to the application code. They require full control over the operating system and middleware. Which cloud service model is most appropriate?
48A cloud customer is reviewing a provider's SOC 2 Type II report. What does this report primarily attest to?
49Which design principle is most directly aimed at avoiding vendor lock-in and ensuring that workloads can be moved between cloud providers with minimal effort?
50In the NIST SP 800-145 definition, which deployment model is described as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers?
51A company uses a hybrid cloud model where sensitive data resides in a private cloud, while compute-intensive analytics run in a public cloud using anonymized data. What is the primary security consideration for this architecture?
52An organization wants to ensure that if they decide to migrate away from their current cloud provider, they can retrieve all data in a usable format and delete it from the provider's systems. Which principle does this best describe?
53In the shared responsibility model for public cloud IaaS, which of the following is typically the responsibility of the cloud customer?
54Which cloud characteristic refers to the ability to automatically scale resources up or down based on demand?
55A cloud architect is designing a multi-tenant SaaS application. Which TWO design principles are critical for ensuring tenant isolation? (Select TWO.)
56An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)
57Which cloud service model allows customers to manage only their data and user access, while the provider manages everything else including the infrastructure, operating system, and applications?
58A financial institution requires a cloud environment that is shared by multiple organizations with common regulatory compliance needs, such as PCI DSS. Which deployment model is most appropriate?
59An organization is evaluating cloud service providers and notices that one provider's SLA offers 99.99% availability for a specific service, while another offers 99.9%. If the service costs $100,000 per month, what is the maximum allowable downtime per month for the 99.99% SLA?
60Which characteristic of cloud computing allows a user to automatically provision computing resources without requiring human interaction with the service provider?
61A company wants to migrate a legacy application to the cloud with minimal re-architecture. They need control over the operating system and middleware but do not want to manage physical hardware. Which service model is most suitable?
62Which cloud design principle is most directly related to ensuring that an organization can migrate workloads from one cloud provider to another without significant re-engineering?
63In a hybrid cloud deployment, which of the following is a critical security consideration?
64An organization is using a public cloud IaaS and wants to ensure they understand which security responsibilities fall on them. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?
65Which cloud design principle ensures that resources can be dynamically adjusted to meet changing demand, often using auto-scaling groups?
66A cloud provider offers a service with an SLA of 99.999% availability. What is the maximum allowable downtime per year in minutes? (Assume 365 days)
67Which of the following is an example of a cloud interoperability standard that facilitates portability of containerized applications across different cloud environments?
68Which NIST essential characteristic of cloud computing allows the provider to dynamically assign and reassign resources to multiple tenants, often using a multi-tenant model?
69A company is considering migrating its customer relationship management (CRM) system to a SaaS provider. Which TWO of the following security responsibilities typically remain with the customer in a SaaS deployment?
70Which cloud service model provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware?
71A healthcare organization is migrating patient records to a public cloud provider. Which of the following is the most critical consideration regarding shared responsibility when using IaaS?
72An organization is designing a multi-cloud strategy using containers to avoid vendor lock-in. Which of the following approaches BEST ensures portability of containerized applications across different cloud providers?
73Which TWO of the following are essential characteristics of cloud computing as defined by NIST SP 800-145?
74A financial institution is evaluating a community cloud deployment shared with other banks. Which TWO security considerations are MOST important for this deployment model?
75Which THREE of the following are benefits of using a hybrid cloud deployment model?
76When evaluating a cloud service provider's SLA, which TWO metrics are MOST relevant for assessing availability and reliability?
77An organization is migrating a legacy application to the cloud and requires reversibility. Which THREE of the following should be considered to ensure the application can be migrated away from the cloud provider in the future?
78A retail company is designing a new cloud architecture for its e-commerce platform. The security team has been asked to define the cloud security architecture. According to the Cloud Security Alliance (CSA) Enterprise Architecture, which of the following is the PRIMARY purpose of the security architecture domain?
79A media production company wants to use a public cloud for rendering video but must retain full control over the guest OS, patching, and runtime configuration. The company does not want to manage physical hardware or hypervisors. Which cloud service model BEST meets these requirements?
80A multinational bank is deploying a hybrid cloud with sensitive workloads on private infrastructure and analytics on a public cloud. The security team must ensure that data classified as confidential never leaves the private environment, while allowing the public cloud to process anonymized datasets. Which cloud deployment model characteristic is MOST relevant to enforcing this boundary?
81A media production company needs to process high-resolution video renders that require tightly coupled, low-latency inter-node communication. The company is evaluating cloud deployment models and wants to retain full control over the hardware, hypervisor, and network fabric while still using cloud burst capacity. Which cloud deployment model BEST meets these requirements?
82A cloud architect is designing a system that must survive the failure of an entire cloud provider region. The application uses a relational database and object storage. Which design approach BEST achieves regional fault tolerance while minimizing data loss and operational complexity?
83A media production company stores and edits large video files on-premises. During peak project periods, editors need to temporarily consume extra compute and storage, but the company wants to keep its existing private cloud and avoid rebuilding workflows. The company wants a solution that lets the private cloud seamlessly use public cloud resources for these bursts without changing how editors access the files. Which cloud deployment model BEST meets this requirement?
84A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?
85A cloud architect is evaluating a public cloud provider for a regulated workload. The provider offers a shared responsibility model. Which TWO of the following are typically the cloud customer's responsibilities under that model? (Choose two.)
86A cloud architect is designing a solution that must ensure data isolation between tenants in a multi-tenant environment. The architect decides to use a virtual private cloud (VPC) per tenant. Which of the following is the PRIMARY security benefit of this approach?
87An enterprise is evaluating a cloud service provider for a workload that handles regulated data. The security architect must assess whether the provider's cloud architecture supports the organization's data residency and audit obligations. Which TWO of the following are the MOST relevant architectural artifacts to request from the provider? (Choose two.)
88A cloud architect is designing a system for a media streaming company that experiences unpredictable spikes in viewer demand during live events. The company wants to minimize infrastructure costs during periods of low demand while maintaining the ability to handle sudden increases in traffic. The architect proposes using a cloud deployment model that provides rapid elasticity and measured service. Which cloud deployment model BEST meets these requirements?
89A startup wants to deploy a customer relationship management (CRM) application without managing any servers, operating systems, or middleware. The vendor hosts the application, and the startup's administrators only create user accounts and configure settings through a web interface. Which cloud service category is being used?
90A small business wants to use a cloud-based email and collaboration suite where the provider manages the application, servers, and operating system. The business only needs to configure user accounts and settings. Which cloud service model is being used?
91A healthcare organization is designing a cloud solution to store and process electronic protected health information (ePHI). The organization must comply with HIPAA and wants to ensure that the cloud service provider (CSP) meets the necessary security and privacy requirements. The organization is evaluating a CSP that offers a Business Associate Agreement (BAA). Which of the following is the MOST critical factor to verify before signing the BAA?
92A startup is developing a new mobile application and wants to minimize infrastructure management while focusing on code development. The team has limited operational resources and prefers a serverless approach. Which cloud service model should they adopt?
93A small business wants to move its email and productivity suite to a cloud service where the provider manages the application, runtime, and underlying infrastructure, and users access the software through a browser. Which cloud service model is being described?
94A media company runs a video transcoding workflow on a public cloud. Jobs arrive unpredictably and must be processed within minutes, but the company wants to minimize cost by using spare capacity that can be reclaimed when demand for full-price capacity rises. The jobs are checkpointed every 30 seconds and can resume on a different host. Which cloud service model and purchasing approach BEST fits this requirement?
95A media company runs a video-transcoding workload on a public cloud IaaS platform. The workload is stateless, tolerant of interruption, and must complete within a 6-hour window at the lowest possible compute cost. The company's architects propose using a cloud service that provisions spare capacity at a significant discount but can reclaim it with a two-minute notice. Which cloud deployment and service model does this describe?
96A government agency is evaluating a cloud deployment model where several agencies with similar missions and compliance obligations will jointly use a cloud environment governed by a shared policy framework. Each agency will retain independent control over its own data and security configurations. Which cloud deployment model does this describe?
97A cloud security manager is designing an exit strategy for a critical SaaS application. The provider's contract permits data export only through a proprietary API that returns records in a non-standard binary format. The manager must reduce the risk of being unable to move data to another provider. Which action BEST addresses this risk?
98A logistics firm runs a customer portal on a public cloud provider. The board wants assurance that a provider outage will not halt order intake. The architect proposes an active-passive deployment in a second region of the same provider. Which design element is MOST critical to validate the recovery time objective?
99A startup is deploying a new web application and wants to avoid managing servers, operating systems, or runtime updates. The developers only want to upload code and have the provider handle scaling, patching, and availability. They do not need control over the underlying infrastructure. Which cloud service model is MOST appropriate?
100A cloud security manager is evaluating the security responsibilities of the cloud provider and the cloud consumer under the shared responsibility model for a PaaS deployment. Which TWO of the following are typically the responsibility of the cloud consumer? (Choose two.)
101A financial services company is migrating its legacy on-premises application to a public cloud IaaS environment. The application currently uses a shared file system that requires strong consistency and low-latency access for transaction processing. The cloud architect must choose a storage solution that meets these performance requirements. Which cloud storage type is MOST appropriate?
102A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?
103A cloud architect is mapping security responsibilities for a SaaS customer relationship management deployment. The provider manages the application, runtime, middleware, operating system, and physical infrastructure. Which security task remains the responsibility of the customer organization?
104A startup wants to deploy a new web application without purchasing servers, and it accepts that its workloads will share physical hardware with other tenants. The founders want the lowest possible upfront cost and the ability to release resources when the product is discontinued. Which cloud deployment model matches these requirements?
105A multinational retailer is selecting a cloud deployment model for a new inventory system. The system must be accessible to stores in several countries, must scale rapidly during seasonal promotions, and must be managed by a third-party provider. The retailer does not want to own or maintain the underlying infrastructure. Which cloud deployment model BEST fits these requirements?
106A cloud architect is designing a multi-tier application that will be deployed in a public cloud. The application must meet strict security and compliance requirements, including data isolation, network segmentation, and encryption of data at rest and in transit. The architect is considering using a virtual private cloud (VPC) and must ensure that the design aligns with the cloud shared responsibility model. Which TWO of the following are the cloud customer's responsibilities under the shared responsibility model? (Choose two.)
107A software vendor wants to offer its analytics product to several hospitals. Each hospital demands that its data reside on infrastructure dedicated to that hospital, that the hospital retain control over patching windows, and that the vendor's other customers never share the same physical hosts. The hospitals also want to share the cost of the common management tooling the vendor provides. Which cloud deployment model BEST matches these requirements?
108A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)
109A cloud security team is reviewing a provider's architecture documentation to assess multi-tenancy risks before migrating regulated workloads. The team wants to verify that logical isolation between tenants is enforced at multiple layers. Which TWO provider controls are MOST directly relevant to preventing one tenant from accessing another tenant's data or processes? (Choose two.)
110A cloud security architect is evaluating a public cloud provider for a new workload that will process regulated data. The architect must document which security responsibilities remain with the cloud customer under the shared responsibility model. Which TWO of the following are customer responsibilities in a public cloud IaaS deployment? (Choose two.)
111A government agency is comparing cloud providers and must prove to auditors that its workloads will remain available and recoverable during a regional provider outage. The agency wants an objective, contractual commitment about the percentage of time a service will be operational, plus a documented financial remedy if the provider misses that target. Which provider artifact should the agency rely on FIRST?
112A startup wants to deploy a new web application without purchasing servers or managing operating systems, and it prefers to focus only on writing code while the provider handles runtime, scaling, and patching. Which cloud service model aligns BEST with this goal?
113A cloud architect is designing a federated identity solution so that employees of a partner company can access a shared SaaS application without creating separate local accounts. The architect must select mechanisms that enable secure cross-domain authentication and attribute exchange. (Choose two.)
114An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?
115An enterprise is evaluating whether to move a legacy customer relationship management system to a cloud provider. The security architect must assess the provider's ability to meet the enterprise's control requirements before signing. Which TWO artifacts or activities BEST provide direct evidence of the provider's security control environment? (Choose two.)
116A cloud architect is documenting the essential characteristics that distinguish a cloud service from traditional hosting for an internal design review. The architect must list the characteristics defined in the widely used cloud reference architecture. Which of the following is one of those essential characteristics?
117A cloud security architect is drafting design requirements for storing regulated data in a public cloud IaaS environment. The requirements must address the risks introduced by resource pooling and multi-tenancy. Which TWO of the following design controls directly mitigate multi-tenancy risks in this environment? (Choose two.)
Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.
The Courseiva CCSP question bank contains 117 questions in the Cloud Concepts, Architecture, and Design domain, covering the 17% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cloud Concepts, Architecture, and Design domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included