CCSP Cloud Concepts, Architecture, and Design Practice Question
A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?
⚠ Common exam trap
Many exam-takers confuse essential cloud characteristics such as resource pooling or measured service with the security controls that actually enforce tenant isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hypervisor-based virtualization and network segmentation
Multi-tenant isolation on shared hardware is achieved through the hypervisor, which partitions memory and CPU, and through network segmentation, which restricts traffic flows between tenants. These architectural controls directly satisfy the requirement that different customers' virtual machines cannot access each other's memory or network traffic even when co-located.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Broad network access
Why it's wrong here
Broad network access means services are reachable over the network through standard mechanisms from diverse client devices. It is a usability and availability characteristic, not an isolation control. Relying on it would not stop a co-resident virtual machine from attempting to access another tenant's memory or internal network traffic.
- ✓
Hypervisor-based virtualization and network segmentation
Why this is correct
The hypervisor enforces memory and CPU isolation between virtual machines on the same host, while virtual network segmentation controls traffic between tenants. Together they directly prevent one customer's VM from reading another's memory or reaching its network segments, which is exactly the isolation the security team requires in a multi-tenant public cloud.
- ✗
Resource pooling
Why it's wrong here
Resource pooling describes the provider aggregating physical and virtual resources to serve multiple consumers dynamically. It explains multi-tenancy economics but does not by itself guarantee isolation; without additional mechanisms, pooled resources could be accessed across tenant boundaries. It is a characteristic of cloud computing, not the control that prevents cross-tenant memory or network access.
- ✗
Measured service
Why it's wrong here
Measured service refers to metering and reporting resource usage for billing and monitoring. While useful for chargeback and capacity planning, it has no role in enforcing memory or network isolation between tenants. It does not prevent cross-tenant access on a shared physical host.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.