CCSP Cloud Concepts, Architecture, and Design Practice Question
A cloud security architect is drafting design requirements for storing regulated data in a public cloud IaaS environment. The requirements must address the risks introduced by resource pooling and multi-tenancy. Which TWO of the following design controls directly mitigate multi-tenancy risks in this environment? (Choose two.)
⚠ Common exam trap
The trap here is accepting a provider guarantee or default encryption as sufficient isolation, when multi-tenancy risk must be mitigated by controls the tenant actually enforces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require strong workload isolation using virtual networks, security groups, and separate tenant identities
Resource pooling means physical infrastructure is shared, so mitigations must either make the data unreadable to anyone outside the tenant or make the logical boundaries between tenants enforceable and auditable. Externally held encryption keys protect confidentiality even if a boundary fails, and virtual network segmentation with distinct identities constrains reachability. Contractual guarantees, disabled logging, and default provider-managed encryption do not change the underlying sharing risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require strong workload isolation using virtual networks, security groups, and separate tenant identities
Why this is correct
Logical segmentation through virtual private networks, security groups, and distinct identity domains keeps one tenant's workloads from reaching another's even when they share physical infrastructure. These controls constrain east-west traffic and administrative reachability, which are the primary paths exploited when isolation is weak. They are standard, effective mitigations for the risks introduced by pooled multi-tenant compute and network resources.
- ✗
Rely on the provider's published service-level agreement to guarantee that tenants never share a physical host
Why it's wrong here
Public IaaS is built on pooled, shared hosts, and service-level agreements address availability and performance commitments rather than promising exclusive physical hardware. Reading an SLA as an isolation guarantee misplaces trust. If exclusive hardware is genuinely required, the architect must select a dedicated host offering, not assume the standard agreement delivers physical separation.
- ✗
Disable all provider-side logging so that telemetry from one tenant cannot be aggregated with another tenant's records
Why it's wrong here
Turning off logging removes the evidence needed for detection, investigation, and compliance, and it does nothing to prevent cross-tenant access. Providers already segregate telemetry per tenant account, so this control solves a problem that does not exist while creating a serious blind spot. It also conflicts with regulatory expectations for audit trails in regulated environments.
- ✓
Enforce cryptographic isolation of data at rest with tenant-managed keys held outside the provider's control
Why this is correct
Because pooled storage may place multiple tenants' data on the same physical media, encrypting data with keys the provider does not hold prevents another tenant, or a provider insider, from reading the content even if a logical boundary fails. Customer-managed keys stored in an external key management system or hardware security module directly address the confidentiality risk that resource pooling creates, making this a valid multi-tenancy mitigation.
- ✗
Move the regulated data into the provider's object storage with default provider-managed encryption only
Why it's wrong here
Default provider-managed encryption protects data at rest from media theft but leaves the provider holding the keys, so it does not prevent provider-side access or address tenant isolation requirements. It also does not secure data in use or in transit between tenants' workloads. On its own, this control is insufficient for the stated risk and is weaker than encryption with externally held keys.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.