Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A financial institution is subject to strict regulatory requirements that mandate data residency and physical control over its infrastructure. At the same time, it wants to leverage cloud bursting for peak loads. Which deployment model should the institution adopt?

⚠ Common exam trap

The trap is focusing only on 'cloud bursting' and picking public cloud, or focusing only on 'physical control' and picking private cloud; the correct answer must satisfy both requirements simultaneously, which only hybrid cloud does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hybrid cloud

A hybrid cloud combines a private cloud (or on-premises infrastructure) with public cloud resources, letting the institution keep regulated data and physical control in its private environment while bursting to public cloud for peak loads. This satisfies data residency and physical control requirements while providing elasticity. Private cloud alone cannot burst to public capacity, and public/community clouds do not give the required physical control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hybrid cloud

    Why this is correct

    Hybrid cloud keeps regulated data on institution-controlled infrastructure, satisfying data residency and physical control mandates, while public cloud capacity absorbs peak loads through bursting. Neither pure public nor private cloud alone meets both constraints simultaneously.

  • ✗

    Private cloud

    Why it's wrong here

    A private cloud alone gives the mandated physical control and residency, but bursting requires capacity that on-premises infrastructure cannot supply on demand. It is tempting because private clouds genuinely satisfy sovereignty and control requirements; it would be correct where those obligations exist without any need to scale beyond owned resources.

  • ✗

    Community cloud

    Why it's wrong here

    A community cloud shares infrastructure among organisations with common concerns, so the institution never obtains the sole physical control its regulator demands, and burst capacity still depends on other tenants' provisioning. It is tempting because community clouds suit shared compliance regimes, and would be correct for several banks jointly meeting identical residency rules.

  • ✗

    Public cloud

    Why it's wrong here

    A public cloud places workloads on provider-owned infrastructure in provider-chosen regions, which cannot satisfy the mandate for physical control, and residency depends entirely on the provider's data-centre locations. It is tempting because public clouds deliver elastic bursting cheaply; it would be correct where no sovereignty or physical-control obligations apply.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.