Courseiva
easyMultiple SelectObjective-mapped

CCSP Practice Question: A security architect is designing a cloud…

A security architect is designing a cloud workload protection platform (CWPP) for a hybrid cloud environment. The architect needs to ensure that security policies are consistently applied across virtual machines running in both on-premises and public cloud environments. Which TWO components are essential for achieving this goal?

⚠ Common exam trap

ISC2 often tests the distinction between network-level controls (SDP, VPC ACLs) and host-level controls (unified agents), leading candidates to mistakenly select network-centric options for workload protection that requires per-VM policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Unified agent software installed on each VM

Unified agent software installed on each VM is essential because it provides a consistent security monitoring and enforcement layer across heterogeneous environments. The agent communicates with the centralized policy management console to receive and enforce policies locally, ensuring that security controls such as file integrity monitoring, vulnerability scanning, and host-based firewall rules are applied uniformly regardless of whether the VM runs on-premises or in a public cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Software-defined perimeter (SDP) architecture

    Why it's wrong here

    Focuses on network segmentation, not workload policy consistency.

  • Virtual private cloud (VPC) network ACLs

    Why it's wrong here

    Network-level controls, not workload-specific.

  • Unified agent software installed on each VM

    Why this is correct

    Enforces policies locally regardless of environment.

  • Centralized policy management console

    Why this is correct

    Enables consistent policy definition and distribution.

  • Infrastructure as code templates

    Why it's wrong here

    Useful for provisioning but not for runtime policy enforcement.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.