Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A financial services company is required to keep customer data within a specific geographic boundary due to regulatory requirements. The company is evaluating cloud deployment models. Which model would best ensure data sovereignty while still providing scalability?

⚠ Common exam trap

The trap is assuming 'private cloud on-premises' is always the most sovereign answer, when the question also demands scalability — community cloud is the model that balances both regulatory boundary and elastic capacity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Community cloud hosted in the required geography

A community cloud hosted within the required geography is provisioned for exclusive use by a specific community of organizations that share concerns (here, regulatory compliance), and it can be located in the mandated jurisdiction while still offering elastic, multi-tenant-style scalability. This satisfies data sovereignty because the infrastructure and data reside within the geographic boundary, and it provides scalability through shared community resources rather than a single organization bearing the full cost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hybrid cloud with public cloud bursting

    Why it's wrong here

    Bursting sends workloads, and potentially data, into a public provider's region, which can cross the mandated boundary. It is tempting because bursting adds scalability without new hardware, and hybrid cloud is a recognised sovereignty pattern — but only when the public tier never processes the regulated data.

  • ✗

    Public cloud with multi-region deployment

    Why it's wrong here

    Multi-region public deployment places replicas in provider-chosen regions, so data can leave the permitted jurisdiction. It is tempting because multi-region designs deliver resilience and low latency, and providers offer in-country regions — but the customer cannot guarantee residency across every replicated copy.

  • ✓

    Community cloud hosted in the required geography

    Why this is correct

    A community cloud is provisioned for exclusive use by a specific community of organisations, so it can be physically hosted within the required geographic boundary, satisfying the data sovereignty constraint. Shared infrastructure among community members still delivers the scalability the company needs.

  • ✗

    Private cloud on-premises

    Why it's wrong here

    On-premises private cloud keeps data inside the boundary but cannot scale elastically without procuring hardware, failing the scalability requirement. It is tempting because it maximises control and sovereignty, and is correct when regulation forbids any external hosting — but here scalability is also demanded.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.