Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A company is migrating to a hybrid cloud and needs to ensure consistent security policies across both on-premises and cloud environments. Which of the following is the MOST critical consideration?

⚠ Common exam trap

CCSP often tests the difference between enabling technologies (like SSO or private links) and the overarching need for consistent policy enforcement, as candidates may focus on specific tools rather than the holistic requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensuring that security policies are uniformly applied and enforced across all environments

The most critical consideration for consistent security policies across hybrid cloud is ensuring that security policies are uniformly applied and enforced across all environments. This ensures that no matter where workloads reside, the same security controls, access rules, and compliance requirements are met, reducing gaps and misconfigurations. While SSO, private connections, and single cloud provider can aid security, they do not guarantee policy consistency; only uniform enforcement does.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing single sign-on (SSO) for all users

    Why it's wrong here

    SSO aids identity management but does not ensure consistent security policies.

  • ✗

    Using dedicated private network connections

    Why it's wrong here

    Dedicated private connections secure transport between environments but carry no mechanism for enforcing uniform security policy across on-premises and cloud workloads. Centralised policy management does. Private connectivity tempts because hybrid architectures depend on it, yet it addresses network path confidentiality rather than policy consistency.

  • ✗

    Choosing the same cloud provider for all public cloud workloads

    Why it's wrong here

    Standardising on one provider simplifies procurement and identity integration but does not deliver consistent policy enforcement across on-premises and cloud environments. A centralised policy management layer does. Provider consolidation tempts because it reduces heterogeneity, yet the stem requires unified controls spanning both environments, including on-premises.

  • ✓

    Ensuring that security policies are uniformly applied and enforced across all environments

    Why this is correct

    Uniform enforcement ensures the same controls govern on-premises and cloud resources, closing gaps where workloads move between environments. This directly addresses the stem's requirement for consistent security policies, since inconsistent application creates exploitable seams during and after migration.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.