CCSP Cloud Concepts, Architecture, and Design Practice Question
A financial institution requires a cloud environment that is shared by multiple organizations with common regulatory compliance needs, such as PCI DSS. Which deployment model is most appropriate?
⚠ Common exam trap
CCSP often tests the distinction between community and public/private clouds by emphasizing 'shared by multiple organizations with common compliance needs,' trapping candidates who default to public cloud for cost or private cloud for security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Community cloud
A community cloud is shared by multiple organizations that have common regulatory or compliance requirements, such as PCI DSS, making it the ideal model for a financial institution needing a compliant shared environment. It provides the cost and scalability benefits of multi-tenancy while meeting sector-specific controls. This matches the definition of community cloud in NIST SP 800-145.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Private cloud
Why it's wrong here
A private cloud is dedicated to one organisation, so it cannot be shared by multiple organisations with common compliance needs. It is tempting because it offers strong isolation and control, and would suit a single institution needing exclusive PCI DSS-scoped infrastructure.
- ✗
Public cloud
Why it's wrong here
A public cloud is open to the general public rather than restricted to organisations sharing common compliance requirements. It is tempting because providers host many tenants and publish PCI DSS attestations, but the community cloud is the model defined by shared concerns among a limited group.
- ✓
Community cloud
Why this is correct
A community cloud is shared by several organisations with common concerns such as PCI DSS compliance, letting the financial institution share infrastructure and cost while meeting its regulatory needs. This matches the stem's requirement for shared infrastructure among organisations with common compliance obligations.
- ✗
Hybrid cloud
Why it's wrong here
Hybrid cloud combines two or more distinct deployment models, which does not by itself create a shared environment for organisations with common compliance needs. It is tempting because it links private and public resources, and would be correct when workloads must span both.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.