Courseiva
easyMultiple Select

CCSP Practice Question: A security architect is designing a cloud…

A security architect is designing a cloud workload protection platform (CWPP) for a hybrid cloud environment. The architect needs to ensure that security policies are consistently applied across virtual machines running in both on-premises and public cloud environments. Which TWO components are essential for achieving this goal?

⚠ Common exam trap

ISC2 often tests the distinction between network-level controls (SDP, VPC ACLs) and host-level controls (unified agents), leading candidates to mistakenly select network-centric options for workload protection that requires per-VM policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unified agent software installed on each VM

Option C (Unified agent software installed on each VM) is essential because a CWPP must have a consistent enforcement point on every workload regardless of location; the same agent binary running on on-premises VMs and public cloud instances provides uniform visibility, vulnerability assessment, and runtime protection across the hybrid estate. Option D (Centralized policy management console) is essential because it is the single control plane where policies are authored once and pushed to all agents, ensuring identical rules are applied in both environments rather than being configured separately per platform. Together, the agent provides distributed enforcement while the console provides centralized definition and orchestration, which is the core CWPP pattern for hybrid cloud. Option A (SDP) is a network-centric zero-trust access model, not a workload protection mechanism, and does not itself apply host security policies. Option B (VPC network ACLs) are stateless subnet-level filters that exist only in the public cloud and cannot enforce policy on on-premises VMs. Option E (IaC templates) automate provisioning and configuration but do not deliver continuous runtime policy enforcement across existing VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Software-defined perimeter (SDP) architecture

    Why it's wrong here

    Software-defined perimeter controls access to resources through identity-based, need-to-know micro-tunnels, but it does not enforce host-level security policies on virtual machines across environments. It is tempting because SDP genuinely secures hybrid access paths, and it would be the right choice when the requirement is hiding internal services from unauthorised users rather than applying consistent workload protection policies.

  • ✗

    Virtual private cloud (VPC) network ACLs

    Why it's wrong here

    VPC network ACLs are stateless subnet-level filters that exist only inside AWS VPCs, so they cannot enforce policy on on-premises virtual machines, breaking the required hybrid consistency. They are tempting because they genuinely segment cloud subnets, and would suit a cloud-only workload confined to a single provider.

  • ✓

    Unified agent software installed on each VM

    Why this is correct

    Unified agent software on each VM enforces policy at the workload itself, so identical rules apply whether the VM runs on-premises or in the public cloud. This satisfies the stem's consistency constraint across both environments, since host-level controls travel with the instance rather than depending on perimeter or cloud-specific tooling.

  • ✓

    Centralized policy management console

    Why this is correct

    A centralized policy management console defines and distributes security policies to every enrolled workload, satisfying the stem's requirement for consistent enforcement across on-premises and public cloud virtual machines. Agents on each VM receive and apply those policies, eliminating per-environment configuration drift and manual duplication.

  • ✗

    Infrastructure as code templates

    Why it's wrong here

    Infrastructure as code templates provision and configure resources declaratively, but they do not enforce runtime security policy across existing workloads. They are tempting because IaC is the right choice for repeatable, version-controlled deployment of new environments, yet the scenario requires continuous policy application to running VMs in both locations.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.