CCSP Cloud Concepts, Architecture, and Design Practice Question
A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?
⚠ Common exam trap
CCSP often tests the misconception that encryption or network speed alone solves hybrid cloud security, but the exam expects recognition that policy consistency and unified governance are the foundation for secure hybrid architectures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining consistent security policies across both environments
In a hybrid cloud model, the most critical security consideration is maintaining consistent security policies across both on-premises and public cloud environments. This ensures that security controls, access management, data protection, and compliance requirements are uniformly enforced, reducing gaps that attackers could exploit. Inconsistencies can lead to misconfigurations, unauthorized access, and data leakage between environments. While network connectivity and encryption are important, they are components of a broader policy consistency strategy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a single cloud provider for both environments
Why it's wrong here
A single provider does not address the hybrid boundary itself; the critical consideration is consistent identity, policy and data-protection controls spanning on-premises and cloud. It tempts because provider consolidation reduces integration surface, which is a valid goal in multi-cloud governance, but it is not the hybrid security requirement.
- ✗
Ensuring high-speed network connectivity
Why it's wrong here
High-speed connectivity addresses latency and throughput, not the security boundary between on-premises and public cloud. The critical consideration is consistent identity and access control across both environments, typically via Microsoft Entra ID. Connectivity is genuinely important for hybrid performance and would be the right answer if the question asked about application responsiveness or data-transfer bottlenecks.
- ✓
Maintaining consistent security policies across both environments
Why this is correct
Hybrid splits workloads across two trust domains, so a single control framework must span both. Consistent policies satisfy the stem's need to govern sensitive on-premises systems and public cloud workloads under one security posture, preventing gaps where data crosses the boundary.
- ✗
Implementing data encryption at rest only
Why it's wrong here
Encryption at rest alone leaves data exposed in transit between on-premises and public cloud, and does nothing for identity, access or workload segmentation across the boundary. It is tempting because encryption at rest satisfies storage-level compliance controls, and would be the right focus where data never leaves a single trust boundary.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.