Question 1,094 of 1,013
SY0-701 Security Architecture Practice Question
A development team is moving a regulated application to a cloud platform. The security architect wants the strongest practical separation from other customers without buying and operating physical servers. Which hosting option is most appropriate?
⚠ Common exam trap
A common mix-up: candidates confuse 'dedicated host' with 'dedicated instance' or assume a shared multi-tenant environment can be secured solely with encryption, overlooking the need for physical isolation in regulated workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A dedicated host or isolated compute offering from the cloud provider.
A dedicated host or isolated compute offering (option B) provides the strongest practical separation because it ensures the application runs on a physical server dedicated solely to that customer, preventing any resource sharing or potential side-channel attacks from other tenants. This meets the regulatory requirement for strong isolation without the cost and operational overhead of purchasing and managing physical servers on-premises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A shared multi-tenant environment with no additional security configuration.
Why it's wrong here
A shared multi-tenant environment without added hardening means your regulated application runs on shared physical hardware with untrusted tenants, offering no resource isolation or protection against side-channel attacks. This lacks the dedicated resource allocation and strict boundary controls required for compliance frameworks like PCI-DSS or FedRAMP, making audit and risk management difficult.
- ✓
A dedicated host or isolated compute offering from the cloud provider.
Why this is correct
A dedicated or isolated compute option provides stronger separation from other tenants while avoiding the need to manage physical hardware directly. It is a common architecture choice for regulated workloads that need enhanced tenant isolation, clearer placement controls, and a stronger compliance story than a standard shared environment.
- ✗
Any public object storage service because the data will be encrypted by default.
Why it's wrong here
Relying on object storage with default encryption only protects data at rest; it does nothing to isolate compute resources, memory, or networking from other cloud tenants. Regulated workloads often need dedicated compute or confidential computing boundaries, not just encrypted blobs, and default keys may not satisfy regulatory key-management requirements.
- ✗
A remote desktop service on the cheapest shared instance available.
Why it's wrong here
A remote desktop service on a low-cost shared instance provides neither adequate performance nor security boundaries, and it's designed for interactive desktop sessions, not background workload processing. The cheapest tier usually means co-tenancy with unknown customers, which undermines tenant separation and violates the principle of least privilege for regulated data.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.