CCSP Cloud Concepts, Architecture, and Design Practice Question
An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)
⚠ Common exam trap
CCSP often tests the misconception that hybrid cloud security is best achieved by giving each environment its own dedicated team and tailored controls, when the exam's correct answer always favors unified, consistent controls across environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unified identity and access management (IAM)
Unified IAM (B) is vital because a hybrid cloud requires a single, consistent authentication and authorization model—using standards like SAML, OAuth 2.0, or OIDC and centralized directory services—so that identities and permissions behave identically across on-premises and cloud environments rather than fragmenting into separate trust domains. Consistent network segmentation and firewall rules (C) are essential because traffic flows between private and public environments must be governed by the same security zones, ACLs, and microsegmentation policies; otherwise lateral movement and misconfigured cross-cloud connectivity create exploitable gaps. Harmonized data encryption and key management (D) is critical because data moving between or stored across environments must use compatible algorithms and centrally governed keys (e.g., via a KMS or HSM with consistent rotation and access policies) to avoid weak links and unmanageable key sprawl. Option A is not required—separate security teams per environment actually undermine consistency by creating divergent policies and fragmented accountability, whereas a unified governance model with shared standards is preferred. Option E is incorrect because using different encryption standards for public versus private clouds introduces interoperability, compliance, and key-management problems; encryption should be harmonized, not differentiated by environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dedicated security team for each environment
Why it's wrong here
Separate per-environment security teams fragment policy ownership, producing divergent controls and inconsistent enforcement across the hybrid estate. A single unified team is the correct consideration; dedicated teams suit organisations with genuinely independent business units, not one hybrid strategy.
- ✓
Unified identity and access management (IAM)
Why this is correct
A single identity plane spanning on-premises and cloud lets one directory govern authentication and authorisation everywhere. Microsoft Entra ID provides this, satisfying the hybrid requirement for consistent access control rather than duplicated, divergent credential stores.
- ✓
Consistent network segmentation and firewall rules
Why this is correct
Identical segmentation and firewall policy applied on both sides stops lateral movement across the hybrid boundary. Without matching rules, a workload permitted on-premises could be exposed once extended to the cloud, breaking the consistent-security constraint.
- ✓
Harmonized data encryption and key management
Why this is correct
Harmonised encryption and key management ensures data remains protected by consistent cryptographic controls whether stored on-premises or in the cloud, directly satisfying the hybrid strategy's need for uniform protection across environments. Divergent key custody or cipher suites between platforms would create gaps that attackers could exploit during data movement.
- ✗
Different encryption standards for public and private clouds
Why it's wrong here
Differing encryption standards between public and private clouds create inconsistent protection and complicate key management and compliance evidence. Uniform standards are the vital consideration; environment-specific standards are defensible only where a regulator explicitly mandates distinct cryptographic requirements for each environment.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.