Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A company is adopting a hybrid cloud strategy. Which TWO security considerations are most critical for maintaining a consistent security posture across environments? (Choose two.)

⚠ Common exam trap

CCSP often tests the misconception that perimeter security or environment-specific teams/keys provide consistency, when in fact hybrid cloud consistency hinges on unified policy and federated identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishing consistent network security policies (e.g., firewall rules)

Option A is correct because consistent network security policies such as firewall rules, security groups, and ACLs ensure that traffic controls are enforced uniformly across on-premises and cloud environments, preventing gaps that attackers could exploit when workloads span both. Option D is correct because identity federation for single sign-on (e.g., SAML 2.0 or OIDC with a central IdP like Entra ID or Okta) provides a unified authentication and authorization model, so users and services have consistent identities and access rights regardless of environment. Option B is incorrect because relying solely on perimeter security fails in hybrid cloud, where assets sit outside a single network boundary and zero-trust, defense-in-depth controls are required. Option C is incorrect because separate security teams per environment create inconsistent policies, duplicated effort, and coordination gaps rather than a unified posture. Option E is incorrect because using different encryption keys per environment is not inherently a consistency requirement; key management should follow a unified governance model (e.g., centralized KMS/HSM with proper key rotation and separation), not simply differ by environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establishing consistent network security policies (e.g., firewall rules)

    Why this is correct

    Hybrid cloud spans on-premises and provider networks, so inconsistent firewall rules create gaps between environments. Uniform network security policies enforce one traffic-filtering baseline across both sides, directly satisfying the stem's demand for a consistent security posture.

  • ✗

    Relying solely on perimeter security

    Why it's wrong here

    Perimeter security assumes a trusted internal network and cannot enforce identity, encryption or logging controls across on-premises and cloud boundaries, so it fails hybrid consistency. It tempts because firewalls and DMZs remain valuable for a single data centre, but it would be correct only for a fully contained, non-distributed environment.

  • ✗

    Deploying separate security teams for each environment

    Why it's wrong here

    Separate per-environment security teams fragment policy ownership, producing divergent controls, inconsistent monitoring and gaps at the hybrid boundary. It tempts because dedicated specialists can deepen expertise in one platform, but it would be correct only where environments are genuinely independent and no unified posture is required.

  • ✓

    Implementing identity federation for single sign-on

    Why this is correct

    Identity federation lets on-premises directories and cloud providers trust one another, so users authenticate once via single sign-on. This unifies access control across both environments, directly satisfying the stem's requirement for a consistent security posture throughout the hybrid estate.

  • ✗

    Using different encryption keys for each environment

    Why it's wrong here

    Distinct encryption keys per environment prevent consistent data protection and complicate cross-environment key management, rotation and access control. It tempts because isolation limits blast radius if one key leaks, but it would be correct only where environments must remain cryptographically segregated with no shared data flows.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.