Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?

⚠ Common exam trap

Many exam-takers confuse essential cloud characteristics such as resource pooling or measured service with the security controls that actually enforce tenant isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hypervisor-based virtualization and network segmentation

Multi-tenant isolation on shared hardware is achieved through the hypervisor, which partitions memory and CPU, and through network segmentation, which restricts traffic flows between tenants. These architectural controls directly satisfy the requirement that different customers' virtual machines cannot access each other's memory or network traffic even when co-located.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broad network access

    Why it's wrong here

    Broad network access means services are reachable over the network through standard mechanisms from diverse client devices. It is a usability and availability characteristic, not an isolation control. Relying on it would not stop a co-resident virtual machine from attempting to access another tenant's memory or internal network traffic.

  • ✓

    Hypervisor-based virtualization and network segmentation

    Why this is correct

    The hypervisor enforces memory and CPU isolation between virtual machines on the same host, while virtual network segmentation controls traffic between tenants. Together they directly prevent one customer's VM from reading another's memory or reaching its network segments, which is exactly the isolation the security team requires in a multi-tenant public cloud.

  • ✗

    Resource pooling

    Why it's wrong here

    Resource pooling describes the provider aggregating physical and virtual resources to serve multiple consumers dynamically. It explains multi-tenancy economics but does not by itself guarantee isolation; without additional mechanisms, pooled resources could be accessed across tenant boundaries. It is a characteristic of cloud computing, not the control that prevents cross-tenant memory or network access.

  • ✗

    Measured service

    Why it's wrong here

    Measured service refers to metering and reporting resource usage for billing and monitoring. While useful for chargeback and capacity planning, it has no role in enforcing memory or network isolation between tenants. It does not prevent cross-tenant access on a shared physical host.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.