Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)

⚠ Common exam trap

The trap here is believing that adopting provider defaults or demanding dedicated hardware substitutes for governance, when control in the cloud comes from enterprise-defined policy and identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An identity and access management framework with least privilege and centralized federation

Governance replaces lost physical control with policy and identity. A data classification and handling policy translates business risk into rules about which services, regions, and protections each data category requires, while a federated identity framework with least privilege governs who and what can reach those resources. Default configurations, dedicated-host mandates, and blanket key prohibitions are either too permissive or too rigid to serve as foundational governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An identity and access management framework with least privilege and centralized federation

    Why this is correct

    In the cloud, identity is the primary security perimeter because there is no physical gate to guard. A federated identity provider with role-based, least-privilege assignments ensures that access to consoles, APIs, and data is centrally granted, reviewed, and revoked. Without this, the enterprise cannot demonstrate who can reach which resources, which is fundamental to governing a multi-tenant environment.

  • ✗

    A mandate that all production data remain on dedicated physical hosts owned by the enterprise

    Why it's wrong here

    Requiring enterprise-owned dedicated hosts contradicts the migration to a public cloud and eliminates the economic and elastic benefits being sought. It also does not by itself produce governance; dedicated hardware still needs identity, policy, and monitoring controls. This is an architecture constraint masquerading as governance and would stall the program rather than mature it.

  • ✓

    A data classification and handling policy that maps each data category to approved cloud services

    Why this is correct

    Once physical custody of media is lost, the enterprise governs through policy and configuration. A classification scheme that states which data categories may reside in which service tiers, regions, and encryption states gives architects and developers an enforceable rule set. It directly compensates for the missing physical controls and underpins every downstream decision about storage, access, and retention.

  • ✗

    A policy prohibiting any use of provider-managed encryption keys for data at rest

    Why it's wrong here

    Prohibiting provider-managed keys is an overbroad technical mandate that ignores risk-based decision making. Many workloads are adequately protected by provider-managed keys with strong access controls, while regulated data may warrant customer-managed keys or a hardware security module. A blanket ban removes flexibility and does not constitute a governance framework; classification-driven key selection does.

  • ✗

    A requirement that all cloud workloads use the provider's default security configuration

    Why it's wrong here

    Provider default configurations are designed for broad compatibility, not for a specific enterprise's risk appetite. Accepting them wholesale cedes governance to the provider and often leaves logging, encryption, and network exposure at permissive settings. Governance requires the enterprise to define and enforce its own baselines, so defaulting to provider settings is the opposite of the intended control.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.