CCSP Cloud Concepts, Architecture, and Design Practice Question
A company is evaluating cloud providers for a critical workload and requires high availability, disaster recovery, and portability. Which THREE factors should the company prioritize in the provider evaluation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Support for open APIs and industry standards
Option A is correct because support for open APIs and industry standards directly enables portability, allowing the company to avoid vendor lock-in and migrate or integrate workloads across providers using well-defined interfaces. Option B is correct because independent audit reports such as SOC 2 and ISO 27001 provide verifiable assurance that the provider's security, availability, and operational controls meet recognized compliance frameworks, which is essential for a critical workload. Option D is correct because SLA guarantees for uptime and availability define the provider's contractual commitment to high availability and provide measurable remedies if service levels are missed, directly supporting the HA/DR requirement. Option C is not a primary evaluation factor here because customer support tiers affect responsiveness and service experience but do not by themselves deliver high availability, disaster recovery, or portability. Option E is also not a primary factor because the number of data center locations alone does not guarantee HA/DR or portability; what matters is how those locations are architected, replicated, and exposed through standards and SLAs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Support for open APIs and industry standards
Why this is correct
Support for open APIs and industry standards directly satisfies the portability constraint by preventing vendor lock-in, letting the workload migrate between providers. Standardised interfaces also underpin resilient multi-provider architectures, so this factor addresses both the portability and high-availability requirements rather than only one.
- ✓
Availability of independent audit reports (e.g., SOC 2, ISO 27001)
Why this is correct
Independent audit reports such as SOC 2 and ISO 27001 evidence that the provider's controls have been externally validated, giving the company assurance over resilience and recoverability commitments. This directly supports the portability and disaster-recovery evaluation criteria by documenting control maturity rather than relying on vendor claims.
- ✗
Provider's customer support tiers
Why it's wrong here
Customer support tiers address response times and escalation paths, not the resilience or portability the workload demands. Support plans are genuinely valuable when operational assistance is contractually required for production incidents, but they neither replicate workloads across regions nor prevent provider lock-in through portable architectures and open standards.
- ✓
SLA guarantees for uptime and availability
Why this is correct
SLA guarantees define contractual uptime and availability commitments, with remedies when targets are missed. They directly satisfy the high-availability requirement in the stem by quantifying expected service continuity and providing measurable thresholds against which the provider's performance can be assessed.
- ✗
Number of data center locations
Why it's wrong here
Counting data centre locations addresses geographic redundancy, but the stem demands portability and disaster recovery, which depend on open standards, exportable data formats and provider-neutral APIs rather than footprint size. It is tempting because a broad regional footprint genuinely supports availability and latency-sensitive placement when portability is not a requirement.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.