CCSP Cloud Concepts, Architecture, and Design Practice Question
A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?
⚠ Common exam trap
The trap here is treating a security appliance such as a web application firewall or hardware security module as if it establishes network isolation, when isolation comes from the virtual network construct itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A virtual private cloud with private subnets and a service endpoint
The requirement combines network isolation, customer-defined addressing and traffic control, and private access to a provider service. A virtual private cloud supplies the isolated network and its subnets, route tables, and gateways; security groups and network ACLs provide the traffic control; and a service endpoint keeps storage traffic on the provider backbone. Content delivery, web application firewalls, and hardware security modules address latency, application attacks, and key protection, not network isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A virtual private cloud with private subnets and a service endpoint
Why this is correct
A virtual private cloud gives the bank a logically isolated network in which it defines its own address ranges, subnets, route tables, and gateways. Private subnets keep the payment API off the public internet while security groups and network ACLs control traffic. A service endpoint lets the VPC reach the provider's object storage over the provider's private backbone instead of the public internet, satisfying the private-connectivity requirement.
- ✗
A web application firewall in front of the API gateway
Why it's wrong here
A web application firewall inspects HTTP traffic and blocks common injection and scripting attacks, and an API gateway manages routing, throttling, and authentication. These are protective and mediating controls layered on top of a network, not a network themselves. They do not provide address-space control, subnet isolation, or private paths to provider services, so the bank would still need an isolated network construct underneath.
- ✗
A content delivery network with origin shielding
Why it's wrong here
A content delivery network caches and distributes content closer to users, improving latency and absorbing volumetric traffic. Origin shielding reduces load on the origin by funneling cache misses through a tier of nodes. Neither creates an isolated network with bank-defined addressing, and both are designed to expose content publicly, so this construct does not satisfy the isolation or private-storage-access requirements.
- ✗
A dedicated hardware security module cluster
Why it's wrong here
A hardware security module cluster protects cryptographic keys and performs signing or encryption operations in tamper-resistant hardware. It is a critical control for payment systems, but it operates at the key-management layer rather than the network layer. It does not define address space, isolate subnets, filter traffic, or create private connectivity to object storage, so it cannot fulfill the architecture requirement in the stem.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.