Courseiva

CCSP · domain

Cloud Concepts, Architecture, and Design

This domain covers cloud reference architecture, deployment and service models, security design principles, and shared responsibility. It is tested through scenario questions on hybrid/multi-cloud, portability, provider assurance reports like SOC 2 Type II, and SLA availability and financial impact calculations.

117 questions28 easy52 medium37 hard

Focused practice

Practice Cloud Concepts, Architecture, and Design questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Concepts, Architecture, and Design

Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.

Shared responsibility across IaaS, PaaS, and SaaS and cloud deployment models

Cloud reference architecture components: BCDR, virtualization, and network security

Provider assurance artifacts such as SOC 2 Type II and ISO/IEC 27001

SLA availability math, downtime, and vendor lock-in mitigation strategies

Watch out for

Common Cloud Concepts, Architecture, and Design exam traps

  • ▸Assuming the provider secures everything; shared responsibility varies by service model and leaves customer duties.
  • ▸Confusing SOC 2 Type II (operating effectiveness over time) with Type I (design at a point in time).
  • ▸Treating 99.99% and 99.9% as similar; small percentage differences create large downtime and financial exposure.

Question index

All Cloud Concepts, Architecture, and Design questions (117)

Click any question to see the full explanation, or start a practice session above.

1

An organization is moving a legacy application to the cloud and wants to minimize changes to the application code. They require full control over the operating system and middleware. Which cloud service model is most appropriate?

Medium
2

A cloud architect is evaluating a public cloud provider for a regulated workload. The provider offers a shared responsibility model. Which TWO of the following are typically the cloud customer's responsibilities under that model? (Choose two.)

Hard
3

An organization wants to deploy a cloud environment where multiple separate agencies with common compliance requirements share the infrastructure, but each agency retains some control over their own resources. Which deployment model best fits this scenario?

Medium
4

Which cloud service model provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware?

Easy
5

When evaluating a cloud service provider's SLA, which TWO metrics are MOST relevant for assessing availability and reliability?

Hard
6

A cloud architect is designing a federated identity solution so that employees of a partner company can access a shared SaaS application without creating separate local accounts. The architect must select mechanisms that enable secure cross-domain authentication and attribute exchange. (Choose two.)

Hard
7

A cloud provider offers a service with an SLA of 99.999% availability. What is the maximum allowable downtime per year in minutes? (Assume 365 days)

Hard
8

A cloud architect is designing a system for a media streaming company that experiences unpredictable spikes in viewer demand during live events. The company wants to minimize infrastructure costs during periods of low demand while maintaining the ability to handle sudden increases in traffic. The architect proposes using a cloud deployment model that provides rapid elasticity and measured service. Which cloud deployment model BEST meets these requirements?

Medium
9

A cloud security manager is designing an exit strategy for a critical SaaS application. The provider's contract permits data export only through a proprietary API that returns records in a non-standard binary format. The manager must reduce the risk of being unable to move data to another provider. Which action BEST addresses this risk?

Hard
10

A financial institution is evaluating a community cloud deployment shared with other banks. Which TWO security considerations are MOST important for this deployment model?

Medium
11

A cloud architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms are essential to prevent tenant data leakage? (Choose two.)

Medium
12

An organization is designing a multi-cloud strategy using containers to avoid vendor lock-in. Which of the following approaches BEST ensures portability of containerized applications across different cloud providers?

Hard
13

In the NIST SP 800-145 definition of cloud computing, which characteristic is described as the capability to rapidly and elastically provision and release resources, often automatically?

Easy
14

A cloud security architect is evaluating a public cloud provider for a new workload that will process regulated data. The architect must document which security responsibilities remain with the cloud customer under the shared responsibility model. Which TWO of the following are customer responsibilities in a public cloud IaaS deployment? (Choose two.)

Hard
15

A company wants to avoid vendor lock-in when adopting cloud services. Which strategy is most effective for achieving portability?

Medium
16

A logistics firm runs a customer portal on a public cloud provider. The board wants assurance that a provider outage will not halt order intake. The architect proposes an active-passive deployment in a second region of the same provider. Which design element is MOST critical to validate the recovery time objective?

Hard
17

A startup wants to deploy a new web application without purchasing servers, and it accepts that its workloads will share physical hardware with other tenants. The founders want the lowest possible upfront cost and the ability to release resources when the product is discontinued. Which cloud deployment model matches these requirements?

Easy
18

Which design principle is MOST directly concerned with the ability to move workloads between cloud providers or back on-premises without significant re-architecture?

Medium
19

An organization is evaluating a cloud service provider and reviewing their SLA. Which THREE metrics are most important for assessing the provider's reliability and accountability? (Choose three.)

Hard
20

A cloud security architect is drafting design requirements for storing regulated data in a public cloud IaaS environment. The requirements must address the risks introduced by resource pooling and multi-tenancy. Which TWO of the following design controls directly mitigate multi-tenancy risks in this environment? (Choose two.)

Hard
21

A cloud security architect is evaluating a CSP for a financial services client. Which of the following audit reports would provide the most comprehensive assurance regarding the CSP's controls over security, availability, processing integrity, confidentiality, and privacy?

Medium
22

A cloud security manager is evaluating the security responsibilities of the cloud provider and the cloud consumer under the shared responsibility model for a PaaS deployment. Which TWO of the following are typically the responsibility of the cloud consumer? (Choose two.)

Medium
23

An enterprise is evaluating whether to move a legacy customer relationship management system to a cloud provider. The security architect must assess the provider's ability to meet the enterprise's control requirements before signing. Which TWO artifacts or activities BEST provide direct evidence of the provider's security control environment? (Choose two.)

Medium
24

A healthcare organization is designing a cloud solution to store and process electronic protected health information (ePHI). The organization must comply with HIPAA and wants to ensure that the cloud service provider (CSP) meets the necessary security and privacy requirements. The organization is evaluating a CSP that offers a Business Associate Agreement (BAA). Which of the following is the MOST critical factor to verify before signing the BAA?

Hard
25

A government agency is evaluating a cloud deployment model where several agencies with similar missions and compliance obligations will jointly use a cloud environment governed by a shared policy framework. Each agency will retain independent control over its own data and security configurations. Which cloud deployment model does this describe?

Hard
26

A media production company stores and edits large video files on-premises. During peak project periods, editors need to temporarily consume extra compute and storage, but the company wants to keep its existing private cloud and avoid rebuilding workflows. The company wants a solution that lets the private cloud seamlessly use public cloud resources for these bursts without changing how editors access the files. Which cloud deployment model BEST meets this requirement?

Medium
27

An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)

Medium
28

Which cloud design principle ensures that resources can be dynamically adjusted to meet changing demand, often using auto-scaling groups?

Medium
29

A cloud architect is designing a solution that must ensure data isolation between tenants in a multi-tenant environment. The architect decides to use a virtual private cloud (VPC) per tenant. Which of the following is the PRIMARY security benefit of this approach?

Hard
30

Which design principle is most directly aimed at avoiding vendor lock-in and ensuring that workloads can be moved between cloud providers with minimal effort?

Medium
31

A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?

Easy
32

A company is evaluating cloud providers for a critical workload and requires high availability, disaster recovery, and portability. Which THREE factors should the company prioritize in the provider evaluation?

Hard
33

A cloud architect is designing a multi-tier application that will be deployed in a public cloud. The application must meet strict security and compliance requirements, including data isolation, network segmentation, and encryption of data at rest and in transit. The architect is considering using a virtual private cloud (VPC) and must ensure that the design aligns with the cloud shared responsibility model. Which TWO of the following are the cloud customer's responsibilities under the shared responsibility model? (Choose two.)

Hard
34

A media production company wants to use a public cloud for rendering video but must retain full control over the guest OS, patching, and runtime configuration. The company does not want to manage physical hardware or hypervisors. Which cloud service model BEST meets these requirements?

Medium
35

In the shared responsibility model for public cloud, which of the following is typically the responsibility of the cloud customer when using IaaS?

Easy
36

A company is adopting a hybrid cloud strategy. Which TWO security considerations are most critical for maintaining a consistent security posture across environments? (Choose two.)

Medium
37

A media company runs a video-transcoding workload on a public cloud IaaS platform. The workload is stateless, tolerant of interruption, and must complete within a 6-hour window at the lowest possible compute cost. The company's architects propose using a cloud service that provisions spare capacity at a significant discount but can reclaim it with a two-minute notice. Which cloud deployment and service model does this describe?

Medium
38

A cloud architect is documenting the essential characteristics that distinguish a cloud service from traditional hosting for an internal design review. The architect must list the characteristics defined in the widely used cloud reference architecture. Which of the following is one of those essential characteristics?

Medium
39

A cloud customer is evaluating a provider's service level agreement (SLA) that guarantees 99.99% availability. What is the maximum allowable downtime per year (in minutes) before the SLA is violated?

Hard
40

A government agency is comparing cloud providers and must prove to auditors that its workloads will remain available and recoverable during a regional provider outage. The agency wants an objective, contractual commitment about the percentage of time a service will be operational, plus a documented financial remedy if the provider misses that target. Which provider artifact should the agency rely on FIRST?

Hard
41

Which cloud service model allows customers to manage only their data and user access, while the provider manages everything else including the infrastructure, operating system, and applications?

Easy
42

A company uses a hybrid cloud model where sensitive data resides in a private cloud, while compute-intensive analytics run in a public cloud using anonymized data. What is the primary security consideration for this architecture?

Medium
43

Which of the following is a key benefit of using a hybrid cloud deployment model?

Medium
44

A cloud architect is designing a system that must survive the failure of an entire cloud provider region. The application uses a relational database and object storage. Which design approach BEST achieves regional fault tolerance while minimizing data loss and operational complexity?

Hard
45

A multinational retailer is selecting a cloud deployment model for a new inventory system. The system must be accessible to stores in several countries, must scale rapidly during seasonal promotions, and must be managed by a third-party provider. The retailer does not want to own or maintain the underlying infrastructure. Which cloud deployment model BEST fits these requirements?

Medium
46

A small business wants to move its email and productivity suite to a cloud service where the provider manages the application, runtime, and underlying infrastructure, and users access the software through a browser. Which cloud service model is being described?

Easy
47

Which of the following is a key benefit of using containers, such as Docker, in a cloud environment to achieve portability?

Medium
48

In the NIST SP 800-145 definition, which deployment model is described as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers?

Easy
49

A media company runs a video transcoding workflow on a public cloud. Jobs arrive unpredictably and must be processed within minutes, but the company wants to minimize cost by using spare capacity that can be reclaimed when demand for full-price capacity rises. The jobs are checkpointed every 30 seconds and can resume on a different host. Which cloud service model and purchasing approach BEST fits this requirement?

Medium
50

A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?

Hard
51

A cloud customer is reviewing a provider's SOC 2 Type II report. What does this report primarily attest to?

Hard
52

Which of the following is an example of a cloud interoperability standard that facilitates portability of containerized applications across different cloud environments?

Medium
53

Which NIST-defined cloud characteristic ensures that resources can be scaled up and down rapidly based on demand?

Easy
54

Which characteristic of cloud computing allows a user to automatically provision computing resources without requiring human interaction with the service provider?

Easy
55

Which cloud characteristic allows a consumer to automatically provision computing resources, such as server time and storage, as needed without requiring human interaction with the service provider?

Medium
56

A company is considering migrating its customer relationship management (CRM) system to a SaaS provider. Which TWO of the following security responsibilities typically remain with the customer in a SaaS deployment?

Medium
57

A cloud provider's SLA guarantees 99.95% uptime for a service. Over a one-year period (365 days), what is the maximum allowed downtime in minutes to meet this SLA?

Hard
58

A company wants to migrate its customer relationship management (CRM) system to the cloud and requires that the provider manages the underlying infrastructure, operating system, and middleware, while the company manages only the application and data. Which cloud service model best meets these requirements?

Easy
59

Which cloud design principle is most directly related to ensuring that an organization can migrate workloads from one cloud provider to another without significant re-engineering?

Hard
60

A media production company needs to process high-resolution video renders that require tightly coupled, low-latency inter-node communication. The company is evaluating cloud deployment models and wants to retain full control over the hardware, hypervisor, and network fabric while still using cloud burst capacity. Which cloud deployment model BEST meets these requirements?

Medium
61

A community cloud is best suited for which scenario?

Medium
62

A cloud architect is designing a solution that must automatically scale compute resources based on real-time demand. The application is stateless and can tolerate brief interruptions. Which cloud design principle is most directly addressed by this requirement?

Medium
63

Which cloud service model provides the customer with the most control over the underlying infrastructure, including operating systems and applications?

Easy
64

In a hybrid cloud deployment, which of the following is a critical security consideration?

Easy
65

An enterprise is evaluating a cloud service provider for a workload that handles regulated data. The security architect must assess whether the provider's cloud architecture supports the organization's data residency and audit obligations. Which TWO of the following are the MOST relevant architectural artifacts to request from the provider? (Choose two.)

Hard
66

An organization is migrating a legacy application to the cloud and wants to minimize vendor lock-in. They plan to use containers orchestrated by Kubernetes. Which design principle is the organization primarily applying?

Hard
67

Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?

Easy
68

A startup is developing a new mobile application and wants to minimize infrastructure management while focusing on code development. The team has limited operational resources and prefers a serverless approach. Which cloud service model should they adopt?

Easy
69

An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?

Easy
70

An organization is evaluating cloud service providers and notices that one provider's SLA offers 99.99% availability for a specific service, while another offers 99.9%. If the service costs $100,000 per month, what is the maximum allowable downtime per month for the 99.99% SLA?

Hard
71

A small business wants to use a cloud-based email and collaboration suite where the provider manages the application, servers, and operating system. The business only needs to configure user accounts and settings. Which cloud service model is being used?

Easy
72

Which TWO of the following are essential characteristics of cloud computing as defined by NIST SP 800-145?

Easy
73

A startup wants to deploy a new web application without purchasing servers or managing operating systems, and it prefers to focus only on writing code while the provider handles runtime, scaling, and patching. Which cloud service model aligns BEST with this goal?

Easy
74

Which characteristic of cloud computing allows a user to provision resources automatically without requiring human interaction with the service provider?

Easy
75

A cloud security architect is designing a multi-tenant SaaS application that must ensure strong isolation between tenants. Which TWO mechanisms are most effective for achieving multitenancy isolation?

Medium
76

In a public cloud IaaS model, which of the following security controls is the cloud customer primarily responsible for implementing?

Medium
77

Which characteristic of cloud computing allows a user to provision computing resources automatically without requiring human interaction with the service provider?

Easy
78

A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?

Medium
79

A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)

Medium
80

A cloud security team is reviewing a provider's architecture documentation to assess multi-tenancy risks before migrating regulated workloads. The team wants to verify that logical isolation between tenants is enforced at multiple layers. Which TWO provider controls are MOST directly relevant to preventing one tenant from accessing another tenant's data or processes? (Choose two.)

Hard
81

A cloud architect is designing a multi-tenant SaaS application. Which TWO design principles are critical for ensuring tenant isolation? (Select TWO.)

Medium
82

An organization needs to migrate a legacy application to the cloud. The application requires full control over the operating system, middleware, and runtime. The team wants to minimize management overhead while retaining OS-level access. Which cloud service model is most appropriate?

Hard
83

A company is migrating to a hybrid cloud and needs to ensure consistent security policies across both on-premises and cloud environments. Which of the following is the MOST critical consideration?

Hard
84

A multinational bank is deploying a hybrid cloud with sensitive workloads on private infrastructure and analytics on a public cloud. The security team must ensure that data classified as confidential never leaves the private environment, while allowing the public cloud to process anonymized datasets. Which cloud deployment model characteristic is MOST relevant to enforcing this boundary?

Hard
85

A security auditor is reviewing a cloud provider's controls to ensure that customer data is appropriately isolated. Which design principle is most directly related to this requirement?

Medium
86

A company plans to deploy a multi-tier application across multiple cloud providers to avoid single points of failure. They need to ensure consistent security policies, including identity federation and network segmentation, across all environments. Which architecture consideration is MOST critical?

Hard
87

Which NIST essential characteristic of cloud computing allows the provider to dynamically assign and reassign resources to multiple tenants, often using a multi-tenant model?

Easy
88

A company is considering moving its customer relationship management (CRM) system to the cloud. The CRM is accessed through a web browser and the provider handles all maintenance, security, and infrastructure. Which cloud service model is being used?

Easy
89

A retail company is designing a new cloud architecture for its e-commerce platform. The security team has been asked to define the cloud security architecture. According to the Cloud Security Alliance (CSA) Enterprise Architecture, which of the following is the PRIMARY purpose of the security architecture domain?

Medium
90

An organization is evaluating a cloud provider's SLA for a critical application. The provider offers a 99.95% uptime SLA with a 10% service credit for each 30-minute downtime period exceeding the threshold. The organization's business impact analysis requires a maximum downtime of 4.38 hours per year. Does the provider's SLA meet this requirement, and what is the annual allowed downtime based on the SLA?

Hard
91

A software vendor wants to offer its analytics product to several hospitals. Each hospital demands that its data reside on infrastructure dedicated to that hospital, that the hospital retain control over patching windows, and that the vendor's other customers never share the same physical hosts. The hospitals also want to share the cost of the common management tooling the vendor provides. Which cloud deployment model BEST matches these requirements?

Medium
92

A financial institution is subject to strict regulatory requirements that mandate data residency and physical control over its infrastructure. At the same time, it wants to leverage cloud bursting for peak loads. Which deployment model should the institution adopt?

Medium
93

Which audit report provides the most comprehensive assurance regarding a cloud provider's controls over a period of time, including controls related to security, availability, processing integrity, confidentiality, and privacy?

Hard
94

In the shared responsibility model for public cloud IaaS, which of the following is typically the responsibility of the cloud customer?

Medium
95

A financial services company is required to keep customer data within a specific geographic boundary due to regulatory requirements. The company is evaluating cloud deployment models. Which model would best ensure data sovereignty while still providing scalability?

Medium
96

A company is designing a multi-cloud strategy to avoid vendor lock-in and ensure portability. They are considering using containers and an open-source orchestration platform. Which of the following is the BEST choice to achieve workload portability across different cloud providers?

Hard
97

Which THREE of the following are benefits of using a hybrid cloud deployment model?

Medium
98

An organization is migrating a legacy application to the cloud and requires reversibility. Which THREE of the following should be considered to ensure the application can be migrated away from the cloud provider in the future?

Hard
99

A healthcare organization is migrating patient records to a public cloud provider. Which of the following is the most critical consideration regarding shared responsibility when using IaaS?

Medium
100

A company wants to migrate a legacy application to the cloud with minimal re-architecture. They need control over the operating system and middleware but do not want to manage physical hardware. Which service model is most suitable?

Medium
101

Which NIST SP 800-145 cloud service model provides the consumer with the ability to deploy applications onto a cloud infrastructure where the consumer does not manage the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment?

Easy
102

A cloud architect is mapping security responsibilities for a SaaS customer relationship management deployment. The provider manages the application, runtime, middleware, operating system, and physical infrastructure. Which security task remains the responsibility of the customer organization?

Medium
103

A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?

Medium
104

In a public cloud IaaS environment, which of the following is the customer responsible for securing, according to the shared responsibility model?

Hard
105

Which cloud characteristic allows a user to automatically provision computing resources without requiring human interaction with the service provider?

Easy
106

A cloud security architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms should be implemented to prevent data leakage between tenants?

Medium
107

An organization is looking for a cloud deployment model that is provisioned for exclusive use by a single organization, but may be owned, managed, and operated by the organization, a third party, or some combination. Which deployment model is this?

Medium
108

Which cloud characteristic refers to the ability to automatically scale resources up or down based on demand?

Easy
109

A startup is deploying a new web application and wants to avoid managing servers, operating systems, or runtime updates. The developers only want to upload code and have the provider handle scaling, patching, and availability. They do not need control over the underlying infrastructure. Which cloud service model is MOST appropriate?

Easy
110

A financial services company is migrating its legacy on-premises application to a public cloud IaaS environment. The application currently uses a shared file system that requires strong consistency and low-latency access for transaction processing. The cloud architect must choose a storage solution that meets these performance requirements. Which cloud storage type is MOST appropriate?

Medium
111

Which of the following is a key consideration when evaluating a cloud service provider's ability to meet compliance requirements for data sovereignty?

Medium
112

A cloud service provider (CSP) offers a shared infrastructure where multiple customers' virtual machines run on the same physical host but are isolated by the hypervisor. Which cloud deployment model does this represent?

Medium
113

An organization is migrating a legacy application to the cloud and wants to maximize elasticity. Which THREE characteristics should the application support to benefit from cloud elasticity?

Hard
114

A financial institution requires a cloud environment that is shared by multiple organizations with common regulatory compliance needs, such as PCI DSS. Which deployment model is most appropriate?

Medium
115

A startup wants to deploy a customer relationship management (CRM) application without managing any servers, operating systems, or middleware. The vendor hosts the application, and the startup's administrators only create user accounts and configure settings through a web interface. Which cloud service category is being used?

Easy
116

An organization wants to ensure that if they decide to migrate away from their current cloud provider, they can retrieve all data in a usable format and delete it from the provider's systems. Which principle does this best describe?

Hard
117

An organization is using a public cloud IaaS and wants to ensure they understand which security responsibilities fall on them. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

Medium

Frequently asked questions

What does the Cloud Concepts, Architecture, and Design domain cover on the CCSP exam?
Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.
How many questions are in this domain?
This page lists all 117 Cloud Concepts, Architecture, and Design questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Concepts, Architecture, and Design questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-ccsp ISC2-CCSP ccsp cloud architecture Practice Questions