Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)

⚠ Common exam trap

CCSP often tests the misconception that hybrid cloud security is best achieved by giving each environment its own dedicated team and tailored controls, when the exam's correct answer always favors unified, consistent controls across environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unified identity and access management (IAM)

Unified IAM (B) is vital because a hybrid cloud requires a single, consistent authentication and authorization model—using standards like SAML, OAuth 2.0, or OIDC and centralized directory services—so that identities and permissions behave identically across on-premises and cloud environments rather than fragmenting into separate trust domains. Consistent network segmentation and firewall rules (C) are essential because traffic flows between private and public environments must be governed by the same security zones, ACLs, and microsegmentation policies; otherwise lateral movement and misconfigured cross-cloud connectivity create exploitable gaps. Harmonized data encryption and key management (D) is critical because data moving between or stored across environments must use compatible algorithms and centrally governed keys (e.g., via a KMS or HSM with consistent rotation and access policies) to avoid weak links and unmanageable key sprawl. Option A is not required—separate security teams per environment actually undermine consistency by creating divergent policies and fragmented accountability, whereas a unified governance model with shared standards is preferred. Option E is incorrect because using different encryption standards for public versus private clouds introduces interoperability, compliance, and key-management problems; encryption should be harmonized, not differentiated by environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dedicated security team for each environment

    Why it's wrong here

    Separate per-environment security teams fragment policy ownership, producing divergent controls and inconsistent enforcement across the hybrid estate. A single unified team is the correct consideration; dedicated teams suit organisations with genuinely independent business units, not one hybrid strategy.

  • ✓

    Unified identity and access management (IAM)

    Why this is correct

    A single identity plane spanning on-premises and cloud lets one directory govern authentication and authorisation everywhere. Microsoft Entra ID provides this, satisfying the hybrid requirement for consistent access control rather than duplicated, divergent credential stores.

  • ✓

    Consistent network segmentation and firewall rules

    Why this is correct

    Identical segmentation and firewall policy applied on both sides stops lateral movement across the hybrid boundary. Without matching rules, a workload permitted on-premises could be exposed once extended to the cloud, breaking the consistent-security constraint.

  • ✓

    Harmonized data encryption and key management

    Why this is correct

    Harmonised encryption and key management ensures data remains protected by consistent cryptographic controls whether stored on-premises or in the cloud, directly satisfying the hybrid strategy's need for uniform protection across environments. Divergent key custody or cipher suites between platforms would create gaps that attackers could exploit during data movement.

  • ✗

    Different encryption standards for public and private clouds

    Why it's wrong here

    Differing encryption standards between public and private clouds create inconsistent protection and complicate key management and compliance evidence. Uniform standards are the vital consideration; environment-specific standards are defensible only where a regulator explicitly mandates distinct cryptographic requirements for each environment.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.