Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?

⚠ Common exam trap

The trap here is treating a security appliance such as a web application firewall or hardware security module as if it establishes network isolation, when isolation comes from the virtual network construct itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A virtual private cloud with private subnets and a service endpoint

The requirement combines network isolation, customer-defined addressing and traffic control, and private access to a provider service. A virtual private cloud supplies the isolated network and its subnets, route tables, and gateways; security groups and network ACLs provide the traffic control; and a service endpoint keeps storage traffic on the provider backbone. Content delivery, web application firewalls, and hardware security modules address latency, application attacks, and key protection, not network isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A virtual private cloud with private subnets and a service endpoint

    Why this is correct

    A virtual private cloud gives the bank a logically isolated network in which it defines its own address ranges, subnets, route tables, and gateways. Private subnets keep the payment API off the public internet while security groups and network ACLs control traffic. A service endpoint lets the VPC reach the provider's object storage over the provider's private backbone instead of the public internet, satisfying the private-connectivity requirement.

  • ✗

    A web application firewall in front of the API gateway

    Why it's wrong here

    A web application firewall inspects HTTP traffic and blocks common injection and scripting attacks, and an API gateway manages routing, throttling, and authentication. These are protective and mediating controls layered on top of a network, not a network themselves. They do not provide address-space control, subnet isolation, or private paths to provider services, so the bank would still need an isolated network construct underneath.

  • ✗

    A content delivery network with origin shielding

    Why it's wrong here

    A content delivery network caches and distributes content closer to users, improving latency and absorbing volumetric traffic. Origin shielding reduces load on the origin by funneling cache misses through a tier of nodes. Neither creates an isolated network with bank-defined addressing, and both are designed to expose content publicly, so this construct does not satisfy the isolation or private-storage-access requirements.

  • ✗

    A dedicated hardware security module cluster

    Why it's wrong here

    A hardware security module cluster protects cryptographic keys and performs signing or encryption operations in tamper-resistant hardware. It is a critical control for payment systems, but it operates at the key-management layer rather than the network layer. It does not define address space, isolate subnets, filter traffic, or create private connectivity to object storage, so it cannot fulfill the architecture requirement in the stem.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.