CCSP Cloud Concepts, Architecture, and Design Practice Question
An organization is migrating a legacy application to the cloud and requires reversibility. Which THREE of the following should be considered to ensure the application can be migrated away from the cloud provider in the future?
⚠ Common exam trap
The trap is that auto-scaling sounds like good cloud architecture, so candidates select it as a 'best practice' without checking whether it actually supports the stated goal (reversibility). Always map each option back to the specific requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using containerization with Kubernetes for workload portability
Option A is correct because containerizing workloads with Kubernetes abstracts the application from the underlying cloud infrastructure, so the same container images and manifests can be redeployed on another provider or on-premises cluster, directly supporting reversibility. Option B is correct because designing with open standards such as OAuth for authentication and REST for service interfaces avoids dependence on a single vendor's proprietary protocols, making it feasible to re-host or re-integrate the application elsewhere. Option E is correct because ensuring data can be exported in standard formats like CSV or JSON prevents data lock-in, allowing the organization to move its data to another platform without loss or costly transformation. Option C is incorrect because proprietary storage and compute APIs increase vendor lock-in and make migration away from the provider harder, which is the opposite of the goal. Option D is incorrect because auto-scaling policies address elasticity and performance, not portability or the ability to exit the cloud provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using containerization with Kubernetes for workload portability
Why this is correct
Containers package the application and its dependencies into a portable image, so Kubernetes can orchestrate that same workload on another provider's cluster. This avoids proprietary runtime lock-in, directly satisfying the reversibility requirement that the application can be migrated away later.
- ✓
Designing the application to use open standards (e.g., OAuth, REST)
Why this is correct
OAuth and REST are vendor-neutral interfaces, so the application's integrations do not depend on proprietary provider APIs. Any replacement platform implementing the same standards can host it, satisfying reversibility by preventing API-level lock-in that would otherwise block migration.
- ✗
Using proprietary APIs for storage and compute
Why it's wrong here
Proprietary APIs lock data and workloads to one provider, obstructing extraction and re-deployment elsewhere. It is tempting because proprietary services can offer performance and integration benefits, but reversibility demands open standards, portable formats and documented export paths instead of vendor-specific interfaces.
- ✗
Implementing auto-scaling policies
Why it's wrong here
Auto-scaling adjusts capacity to demand; it neither stores data in portable formats nor documents exit procedures, so it does nothing for reversibility. It is tempting because elasticity is a core cloud benefit, but the correct considerations are open APIs, data export formats and contractual exit or transition assistance clauses.
- ✓
Ensuring data can be exported in standard formats (e.g., CSV, JSON)
Why this is correct
Exporting data as CSV or JSON keeps it in provider-neutral, machine-readable form, so it can be loaded into another platform's database without proprietary tooling. This satisfies reversibility by removing data gravity and format lock-in as obstacles to migrating away.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.