CCSP Cloud Concepts, Architecture, and Design Practice Question
A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)
⚠ Common exam trap
The trap here is believing that adopting provider defaults or demanding dedicated hardware substitutes for governance, when control in the cloud comes from enterprise-defined policy and identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An identity and access management framework with least privilege and centralized federation
Governance replaces lost physical control with policy and identity. A data classification and handling policy translates business risk into rules about which services, regions, and protections each data category requires, while a federated identity framework with least privilege governs who and what can reach those resources. Default configurations, dedicated-host mandates, and blanket key prohibitions are either too permissive or too rigid to serve as foundational governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An identity and access management framework with least privilege and centralized federation
Why this is correct
In the cloud, identity is the primary security perimeter because there is no physical gate to guard. A federated identity provider with role-based, least-privilege assignments ensures that access to consoles, APIs, and data is centrally granted, reviewed, and revoked. Without this, the enterprise cannot demonstrate who can reach which resources, which is fundamental to governing a multi-tenant environment.
- ✗
A mandate that all production data remain on dedicated physical hosts owned by the enterprise
Why it's wrong here
Requiring enterprise-owned dedicated hosts contradicts the migration to a public cloud and eliminates the economic and elastic benefits being sought. It also does not by itself produce governance; dedicated hardware still needs identity, policy, and monitoring controls. This is an architecture constraint masquerading as governance and would stall the program rather than mature it.
- ✓
A data classification and handling policy that maps each data category to approved cloud services
Why this is correct
Once physical custody of media is lost, the enterprise governs through policy and configuration. A classification scheme that states which data categories may reside in which service tiers, regions, and encryption states gives architects and developers an enforceable rule set. It directly compensates for the missing physical controls and underpins every downstream decision about storage, access, and retention.
- ✗
A policy prohibiting any use of provider-managed encryption keys for data at rest
Why it's wrong here
Prohibiting provider-managed keys is an overbroad technical mandate that ignores risk-based decision making. Many workloads are adequately protected by provider-managed keys with strong access controls, while regulated data may warrant customer-managed keys or a hardware security module. A blanket ban removes flexibility and does not constitute a governance framework; classification-driven key selection does.
- ✗
A requirement that all cloud workloads use the provider's default security configuration
Why it's wrong here
Provider default configurations are designed for broad compatibility, not for a specific enterprise's risk appetite. Accepting them wholesale cedes governance to the provider and often leaves logging, encryption, and network exposure at permissive settings. Governance requires the enterprise to define and enforce its own baselines, so defaulting to provider settings is the opposite of the intended control.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.