Courseiva

CCNA Cloud Concepts, Architecture, and Design Questions

75 of 117 questions · Page 1/2 · Cloud Concepts, Architecture, and Design · Answers revealed

1
MCQmedium

An organization is moving a legacy application to the cloud and wants to minimize changes to the application code. They require full control over the operating system and middleware. Which cloud service model is most appropriate?

A.PaaS
B.SaaS
C.IaaS
D.FaaS
AnswerC

IaaS supplies virtualised compute, storage, and networking while leaving the guest operating system and middleware under customer control. This satisfies the requirement for full OS and middleware control with minimal code changes, unlike PaaS, which abstracts the platform layer.

Why this answer

IaaS provides the customer with virtualized compute, storage, and networking while giving them full control over the operating system, middleware, and runtime — exactly what a legacy application needing minimal code changes requires. The customer manages the guest OS and above, while the provider handles the physical infrastructure and hypervisor. This makes IaaS the most appropriate model for lift-and-shift migrations with OS-level control requirements.

Exam trap

CCSP often tests the control-versus-management tradeoff across service models; the trap is choosing PaaS because it 'sounds modern,' ignoring the requirement for full OS and middleware control.

How to eliminate wrong answers

Option A is wrong because PaaS abstracts the OS and middleware, so the customer cannot control the operating system and would likely need to modify the application to fit platform constraints. Option B is wrong because SaaS delivers a fully managed application, offering no control over OS or middleware and typically requiring significant application changes or replacement. Option D is wrong because FaaS (serverless functions) abstracts everything below the function code, imposes execution time limits, and is unsuitable for a legacy application requiring persistent OS-level control.

2
Multi-Selecthard

A cloud architect is evaluating a public cloud provider for a regulated workload. The provider offers a shared responsibility model. Which TWO of the following are typically the cloud customer's responsibilities under that model? (Choose two.)

Select 2 answers
A.Configuring identity and access management policies
B.Maintaining the physical network fabric between availability zones
C.Classifying and protecting data stored in the cloud
D.Patching the hypervisor
E.Managing physical access to the data center
AnswersA, C

Identity and access management policies are configured by the customer to control who can access their resources and data. The provider secures the underlying identity platform, but the customer defines users, roles, permissions, and federation. This is a core customer responsibility in public cloud, especially for regulated workloads where least privilege must be enforced.

Why this answer

Under the shared responsibility model, the customer is responsible for security in the cloud, which includes configuring identity and access management policies and classifying and protecting data. Physical access, hypervisor patching, and physical network fabric are provider responsibilities. Regulated workloads require the customer to focus on data protection and access control while relying on the provider for infrastructure security.

Exam trap

The trap here is assuming the provider secures everything, when the customer still owns identity configuration and data protection even in a public cloud.

3
MCQmedium

An organization wants to deploy a cloud environment where multiple separate agencies with common compliance requirements share the infrastructure, but each agency retains some control over their own resources. Which deployment model best fits this scenario?

A.Hybrid cloud
B.Public cloud
C.Private cloud
D.Community cloud
AnswerD

A community cloud is provisioned for exclusive use by a specific community of organisations sharing common compliance concerns, yet each participating agency can retain control over its own resources. This matches the stem's requirement for shared infrastructure among agencies with common compliance needs.

Why this answer

A community cloud is a deployment model where infrastructure is shared by several organizations with common concerns (e.g., compliance, security, jurisdiction). In this scenario, multiple agencies with common compliance requirements share the infrastructure while each retains control over their own resources, which aligns exactly with the community cloud model. This model balances cost-efficiency with the specific needs of a defined community.

Exam trap

The trap is confusing community cloud with public or hybrid cloud; candidates often focus on 'shared infrastructure' and pick public cloud, ignoring the 'common compliance requirements' and 'multiple agencies' that define a community cloud.

How to eliminate wrong answers

Option A is wrong because a hybrid cloud combines private and public clouds, typically for workload portability, not for sharing among multiple agencies with common compliance needs. Option B is wrong because a public cloud is owned by a single provider and shared by the general public, not tailored to a specific community's compliance requirements. Option C is wrong because a private cloud is dedicated to a single organization, which would not allow multiple agencies to share infrastructure while retaining control.

4
MCQeasy

Which cloud service model provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Function as a Service (FaaS)
D.Infrastructure as a Service (IaaS)
AnswerA

PaaS supplies the managed runtime, middleware and operating system, so the customer deploys code and manages only applications and data. This satisfies the stem's constraint that the underlying OS and hardware remain the provider's responsibility, unlike IaaS where the guest OS is customer-managed.

Why this answer

Platform as a Service (PaaS) provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware. This matches the description exactly.

Exam trap

CCSP often tests the differences between IaaS, PaaS, and SaaS, and candidates may confuse PaaS with IaaS or FaaS, especially when the question emphasizes managing applications but not the OS.

How to eliminate wrong answers

Option B is wrong because Software as a Service (SaaS) provides fully functional applications managed by the provider, and the customer does not manage the application or data in the same way; they just use the software. Option C is wrong because Function as a Service (FaaS) is a subset of serverless computing where the customer deploys functions, but it is not the broad service model described; FaaS abstracts even more, and the customer only manages the function code. Option D is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources, but the customer manages the operating system and middleware, which contradicts the requirement of not managing the OS.

5
Multi-Selecthard

When evaluating a cloud service provider's SLA, which TWO metrics are MOST relevant for assessing availability and reliability?

Select 2 answers
A.Uptime percentage (e.g., 99.99%)
B.Support ticket response time
C.Maximum throughput per instance
D.Average latency for API calls
E.Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
AnswersA, E

Uptime percentage quantifies the proportion of agreed service time the provider's service remains operational, directly measuring availability. It is the primary SLA metric for assessing whether the provider meets its committed reliability target over the contract period.

Why this answer

Option A (Uptime percentage, e.g., 99.99%) is correct because uptime is the primary SLA metric that quantifies availability, directly expressing the percentage of time the service is operational and typically tied to service credits when the committed threshold is missed. Option E (Recovery Time Objective (RTO) and Recovery Point Objective (RPO)) is correct because these metrics define reliability in terms of how quickly service is restored after an outage (RTO) and how much data loss is tolerable (RPO), which are core to assessing a provider's resilience and disaster recovery commitments. Option B (Support ticket response time) relates to support quality and incident handling, not directly to availability or reliability guarantees.

Option C (Maximum throughput per instance) is a performance/capacity metric rather than an availability or reliability measure. Option D (Average latency for API calls) is a performance metric that affects responsiveness but does not by itself indicate availability or reliability.

Exam trap

CCSP often tests the distinction between availability and reliability metrics; candidates may confuse performance metrics (latency, throughput) with availability/reliability, or overlook RTO/RPO as key reliability indicators.

6
Multi-Selecthard

A cloud architect is designing a federated identity solution so that employees of a partner company can access a shared SaaS application without creating separate local accounts. The architect must select mechanisms that enable secure cross-domain authentication and attribute exchange. (Choose two.)

Select 2 answers
A.OpenID Connect (OIDC)
B.Data Loss Prevention (DLP) endpoint agent
C.Internet Protocol Security (IPsec) transport mode
D.Dynamic Host Configuration Protocol (DHCP) snooping
E.Security Assertion Markup Language (SAML) 2.0
AnswersA, E

OIDC builds on OAuth 2.0 to provide federated authentication and delivers identity attributes through the ID token and UserInfo endpoint. It enables partner users to authenticate through their home identity provider and access the SaaS application without local accounts, satisfying the cross-domain authentication and attribute exchange requirement.

Why this answer

Federated identity requires protocols that carry authentication assertions and user attributes across security domains. SAML 2.0 and OpenID Connect both do this, allowing partner employees to authenticate with their home identity provider and access the shared SaaS application without local accounts. IPsec, DLP endpoint agents, and DHCP snooping operate at network or data layers and cannot federate identities.

Exam trap

The trap here is selecting a transport security mechanism such as IPsec, which protects packets but never authenticates users across domains.

7
MCQhard

A cloud provider offers a service with an SLA of 99.999% availability. What is the maximum allowable downtime per year in minutes? (Assume 365 days)

A.8.76 minutes
B.5.26 minutes
C.0.526 minutes
D.52.6 minutes
AnswerB

A 99.999% availability SLA permits 0.001% annual downtime. With 365 days, that equals 525,600 minutes per year, so the allowable outage is 525,600 × 0.00001 = 5.256 minutes, rounded to 5.26 minutes. This satisfies the stem's five-nines constraint precisely.

Why this answer

An SLA of 99.999% availability (often called 'five nines') allows for a maximum of 5.26 minutes of downtime per year. This is calculated by taking the total minutes in a year (365 days × 24 hours × 60 minutes = 525,600 minutes) and multiplying by the allowed unavailability (100% - 99.999% = 0.001%, or 0.00001 as a decimal). 525,600 × 0.00001 = 5.256 minutes, which rounds to 5.26 minutes.

Exam trap

CCSP often tests the ability to calculate downtime from availability percentages; the trap is misplacing the decimal point or using the wrong number of minutes in a year (e.g., 525,600 vs 525,960 for leap year). Candidates may also confuse 99.999% with 99.99%.

How to eliminate wrong answers

Option A is wrong because 8.76 minutes corresponds to 99.998% availability (or 99.999% if calculated with 365.25 days? Actually 8.76 minutes is for 99.9983%? Let's check: 525,600 × 0.0000167 = 8.76, which is 99.99833% availability, not five nines). Option C is wrong because 0.526 minutes is one-tenth of the correct value, corresponding to 99.9999% availability (six nines). Option D is wrong because 52.6 minutes is ten times the correct value, corresponding to 99.99% availability (four nines).

8
MCQmedium

A cloud architect is designing a system for a media streaming company that experiences unpredictable spikes in viewer demand during live events. The company wants to minimize infrastructure costs during periods of low demand while maintaining the ability to handle sudden increases in traffic. The architect proposes using a cloud deployment model that provides rapid elasticity and measured service. Which cloud deployment model BEST meets these requirements?

A.Private cloud
B.Hybrid cloud
C.Public cloud
D.Community cloud
AnswerC

A public cloud provides on-demand self-service, rapid elasticity, and measured service, allowing the streaming company to scale resources up during spikes and down during low demand, paying only for what is used. This aligns with the requirements of minimizing costs during low demand while handling sudden increases in traffic.

Why this answer

The public cloud model is designed to provide on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. These characteristics allow the media streaming company to automatically scale resources during live events and reduce costs when demand is low. Private, community, and hybrid models do not offer the same combination of rapid elasticity and cost efficiency for unpredictable workloads.

Exam trap

The trap here is assuming that a hybrid cloud is always the best choice for handling variable demand because it combines private and public resources, but the scenario does not require a private component, making public cloud the simpler and more cost-effective solution.

9
MCQhard

A cloud security manager is designing an exit strategy for a critical SaaS application. The provider's contract permits data export only through a proprietary API that returns records in a non-standard binary format. The manager must reduce the risk of being unable to move data to another provider. Which action BEST addresses this risk?

A.Enable multi-factor authentication for all administrative accounts on the SaaS platform
B.Negotiate a contractual right to receive data in a documented, non-proprietary format at any time
C.Require the provider to publish its API documentation to the customer's security team
D.Replicate the SaaS data nightly to an on-premises backup appliance using the same API
AnswerB

Contractual guarantees of portable, documented, non-proprietary export formats directly mitigate lock-in by ensuring data can be consumed by another provider's tools. Because the technical export path is proprietary, only a negotiated right to standard formats removes the dependency, making this the most effective control for the stated risk.

Why this answer

The core risk is that data can only be extracted in a proprietary binary format, which prevents migration to another provider. The strongest mitigation is a contractual right to receive the data in a documented, non-proprietary format on demand. Authentication hardening, backups through the same API, and API documentation do not remove the format dependency, so they cannot resolve the portability problem.

Exam trap

The trap here is treating a nightly backup through the same proprietary API as a portability control, when it only replicates the lock-in.

10
Multi-Selectmedium

A financial institution is evaluating a community cloud deployment shared with other banks. Which TWO security considerations are MOST important for this deployment model?

Select 2 answers
A.Minimizing network bandwidth to reduce costs
B.The provider assumes full responsibility for all security controls
C.Use of dedicated physical servers for each tenant
D.Ensuring strong isolation between tenant data and workloads
E.Compliance with common regulatory standards (e.g., PCI-DSS, SOX)
AnswersD, E

Tenant isolation is critical in a community cloud because multiple banks share the same infrastructure. Strong logical separation of data and workloads prevents one tenant from accessing another's resources, satisfying the constraint that shared infrastructure must not compromise confidentiality between competing financial institutions.

Why this answer

In a community cloud shared by multiple banks, option D is essential because tenants share the same underlying infrastructure, so strong logical isolation of data and workloads (via mechanisms like VLANs, hypervisor isolation, encryption, and access controls) is required to prevent cross-tenant data leakage or interference. Option E is also critical because a community cloud serving financial institutions must satisfy shared regulatory obligations such as PCI-DSS for cardholder data and SOX for financial reporting, and the provider and tenants must jointly demonstrate compliance. Option A is not a security consideration but a cost/performance concern, and minimizing bandwidth could even undermine security monitoring and logging.

Option B is incorrect because in cloud deployments security responsibility is shared, not fully transferred to the provider. Option C is not required for a community cloud, since multi-tenancy on shared physical servers is normal as long as isolation is enforced.

Exam trap

CCSP often tests the misconception that community cloud providers assume full security responsibility, when in fact the shared responsibility model still applies and tenants must secure their own data and configurations.

11
Multi-Selectmedium

A cloud architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms are essential to prevent tenant data leakage? (Choose two.)

Select 2 answers
A.Geographic isolation
B.Network isolation (e.g., VLANs, VPCs)
C.Shared storage volume encryption
D.Logical data isolation (e.g., database per tenant)
E.Hypervisor isolation
AnswersB, D

VLANs and VPCs segment tenant traffic at the network layer, preventing one tenant's workloads from reaching another's and blocking lateral movement. This satisfies the stem's requirement for essential isolation mechanisms preventing tenant data leakage in the multi-tenant SaaS application.

Why this answer

Option B (Network isolation, e.g., VLANs, VPCs) is correct because segmenting tenant traffic at Layer 2/Layer 3 with VLANs or cloud VPCs and security groups prevents cross-tenant lateral movement and unauthorized access to another tenant's resources, which is a foundational control against data leakage in multi-tenant SaaS. Option D (Logical data isolation, e.g., database per tenant) is correct because separating tenant records through per-tenant databases, schemas, or tenant-ID row-level filtering ensures that queries and application logic cannot read or modify another tenant's data even if a request is misrouted. Option A (Geographic isolation) is not essential here because placing tenants in different regions addresses residency and latency, not the core logical separation needed to stop data leakage between tenants sharing the same application.

Option C (Shared storage volume encryption) is insufficient because encrypting a shared volume protects data at rest but does not prevent one tenant's application context from accessing another tenant's records on that same volume. Option E (Hypervisor isolation) is not the essential mechanism for this scenario because it separates VMs at the virtualization layer, whereas multi-tenant SaaS typically shares application and database tiers where network and logical data isolation are the decisive controls.

Exam trap

CCSP often tests the misconception that encryption or hypervisor isolation alone prevents tenant data leakage, when logical and network isolation are the controls that actually enforce tenant boundaries.

12
MCQhard

An organization is designing a multi-cloud strategy using containers to avoid vendor lock-in. Which of the following approaches BEST ensures portability of containerized applications across different cloud providers?

A.Use cloud provider-specific container services like Amazon ECS with proprietary APIs.
B.Use nested containers to abstract the underlying cloud provider.
C.Standardize on Docker images and Kubernetes orchestration with open-source tooling.
D.Deploy containers directly on virtual machines without an orchestration layer.
AnswerC

Standardising on Docker images with Kubernetes orchestration and open-source tooling removes provider-specific dependencies, so the same artefacts deploy unchanged across clouds. This directly satisfies the stem's portability requirement, unlike managed proprietary services that bind workloads to one vendor.

Why this answer

Standardizing on Docker images and Kubernetes orchestration with open-source tooling (C) best ensures portability because Docker images are OCI-compliant and Kubernetes is a CNCF-graduated project supported by all major cloud providers. This combination avoids proprietary APIs and allows workloads to be moved between AWS EKS, Azure AKS, Google GKE, or on-premises clusters with minimal changes. Open-source tooling further reduces lock-in by providing consistent APIs and configuration formats.

Exam trap

CCSP often tests the assumption that using containers automatically guarantees portability, when in fact proprietary orchestration services and cloud-specific integrations can reintroduce lock-in.

How to eliminate wrong answers

Option A is wrong because using cloud provider-specific services like Amazon ECS with proprietary APIs creates vendor lock-in — migrating to another cloud would require rewriting task definitions, IAM policies, and networking configurations. Option B is wrong because nested containers add complexity and do not abstract the underlying cloud provider; they still run on the provider's infrastructure and do not solve portability of orchestration or networking. Option D is wrong because deploying containers directly on VMs without an orchestration layer lacks the abstraction and automation needed for portability; it ties deployments to specific VM configurations and manual processes, making cross-cloud migration difficult.

13
MCQeasy

In the NIST SP 800-145 definition of cloud computing, which characteristic is described as the capability to rapidly and elastically provision and release resources, often automatically?

A.Rapid elasticity
B.Resource pooling
C.Broad network access
D.Measured service
AnswerA

Rapid elasticity is the NIST SP 800-145 characteristic describing capabilities provisioned and released elastically, often automatically, to scale outward and inward with demand. Measured service, on-demand self-service, and resource pooling describe different aspects of the same definition.

Why this answer

NIST SP 800-145 defines rapid elasticity as the capability to elastically provision and release resources, in some cases automatically, to scale rapidly outward and inward commensurate with demand. The phrase 'rapidly and elastically provision and release resources, often automatically' maps directly to this characteristic. It is one of the five essential characteristics of cloud computing alongside on-demand self-service, broad network access, resource pooling, and measured service.

Exam trap

The trap is that 'elasticity' and 'scalability' are often used interchangeably in casual conversation, but NIST treats rapid elasticity specifically as automatic, bidirectional provisioning and release — candidates who pick 'resource pooling' confuse sharing with scaling.

How to eliminate wrong answers

Option B is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are pooled to serve multiple consumers, with location independence — it is about sharing, not scaling speed. Option C is wrong because broad network access means capabilities are available over the network via standard mechanisms (e.g., HTTP, APIs) from diverse client platforms. Option D is wrong because measured service refers to metering and pay-per-use billing through automatic control and optimization of resource use.

14
Multi-Selecthard

A cloud security architect is evaluating a public cloud provider for a new workload that will process regulated data. The architect must document which security responsibilities remain with the cloud customer under the shared responsibility model. Which TWO of the following are customer responsibilities in a public cloud IaaS deployment? (Choose two.)

Select 2 answers
A.Managing guest operating system patches and updates
B.Maintaining the provider's hypervisor and virtualization platform
C.Ensuring the physical network backbone between data centers is redundant
D.Securing the physical facilities that house the servers
E.Configuring identity and access management policies for cloud resources
AnswersA, E

In IaaS, the customer is responsible for the guest operating system, including patching, hardening, and updates. The provider secures the virtualization layer and physical infrastructure, but the customer must maintain the OS inside its virtual machines. This responsibility is a core part of the shared responsibility model for IaaS and must be documented accordingly.

Why this answer

In public cloud IaaS, the provider secures facilities, hardware, and the virtualization platform, while the customer secures the guest operating system and its own identity and access management configurations. Guest OS patching and IAM policy management are therefore customer responsibilities, whereas physical facilities, hypervisor maintenance, and physical network redundancy remain with the provider.

Exam trap

The trap here is assuming that because the provider owns the cloud, it also owns every layer above the hypervisor, including guest OS patching and customer IAM policies.

15
MCQmedium

A company wants to avoid vendor lock-in when adopting cloud services. Which strategy is most effective for achieving portability?

A.Using proprietary APIs from the cloud provider
B.Subscribing to a single cloud provider's managed services
C.Using proprietary data formats
D.Adopting open standards and open-source APIs like Kubernetes and Terraform
AnswerD

Open standards and open-source APIs such as Kubernetes and Terraform decouple workloads from any single provider's proprietary interfaces, so components can be redeployed elsewhere. This directly satisfies the stem's portability constraint by removing the vendor-specific dependencies that cause lock-in.

Why this answer

Using open standards and APIs ensures that workloads can be moved between providers. Using proprietary APIs, single provider services, or managed services increases lock-in.

16
MCQhard

A logistics firm runs a customer portal on a public cloud provider. The board wants assurance that a provider outage will not halt order intake. The architect proposes an active-passive deployment in a second region of the same provider. Which design element is MOST critical to validate the recovery time objective?

A.A documented failover runbook that has never been executed
B.Regularly scheduled failover tests that measure actual recovery time and data loss
C.A service level agreement from the provider guaranteeing 99.99 percent regional availability
D.Cross-region replication of the database with asynchronous commit enabled
AnswerB

The only credible way to validate a recovery time objective and recovery point objective is to exercise the failover and measure how long the standby region takes to serve production traffic and how much data is missing. Scheduled game days expose stale DNS records, replication lag, and capacity shortfalls, and the measured results become the evidence the board needs.

Why this answer

Recovery objectives are validated by measurement, not by documentation or provider guarantees. Scheduled failover exercises reveal the real elapsed time to restore service and the true data loss window, accounting for DNS time-to-live, database promotion, and application reconnection. Replication and agreements enable recovery, but only testing produces the evidence that the stated recovery time objective is achievable.

Exam trap

The trap here is treating a provider availability commitment or a configured replication link as proof of business continuity, when only an executed failover measures real recovery time.

17
MCQeasy

A startup wants to deploy a new web application without purchasing servers, and it accepts that its workloads will share physical hardware with other tenants. The founders want the lowest possible upfront cost and the ability to release resources when the product is discontinued. Which cloud deployment model matches these requirements?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerB

A public cloud is owned by a provider and offers self-service, on-demand resources to any customer over the network, with no capital purchase and pay-per-use billing. Sharing physical infrastructure with other tenants is inherent to the model and is what enables the low entry cost. Resources can be released when the product is discontinued, matching every stated requirement.

Why this answer

The public cloud model is defined by provider ownership, multi-tenant shared infrastructure, self-service provisioning, and consumption-based billing. Those traits deliver the lowest barrier to entry and allow the startup to stop paying when the product ends. Private and community clouds require dedicated or consortium arrangements, while hybrid assumes a pre-existing private footprint to integrate.

Exam trap

The trap here is equating shared physical hardware with inadequate security, when multi-tenancy is a defining economic trait of the public cloud rather than a disqualifying weakness.

18
MCQmedium

Which design principle is MOST directly concerned with the ability to move workloads between cloud providers or back on-premises without significant re-architecture?

A.Reversibility
B.Portability
C.Isolation
D.Elasticity
AnswerB

Portability directly addresses avoiding provider lock-in by ensuring workloads can migrate between clouds or back on-premises without re-architecture. It satisfies the stem's constraint of relocation without significant redesign, distinguishing it from interoperability, which concerns systems communicating across providers rather than moving between them.

Why this answer

Portability is the design principle concerned with the ability to move workloads, data, and applications between cloud providers or back on-premises without significant re-architecture. It emphasizes avoiding proprietary lock-in through open standards, containers, and abstraction layers. The scenario's phrase 'move workloads between cloud providers or back on-premises without significant re-architecture' is the definition of portability.

Exam trap

The trap is the close pairing of portability and reversibility — candidates often pick reversibility because both involve leaving a provider, but the question's emphasis on moving workloads without re-architecture points to portability.

How to eliminate wrong answers

Option A is wrong because reversibility is the related but distinct principle of being able to exit a cloud provider and return to on-premises or another provider — it focuses on the exit path and data retrieval, while portability focuses on the technical ease of moving the workload itself. Option C is wrong because isolation concerns separating tenants, workloads, or data to prevent cross-contamination and is unrelated to workload mobility. Option D is wrong because elasticity is about automatic scaling of resources with demand, not about moving workloads between environments.

19
Multi-Selecthard

An organization is evaluating a cloud service provider and reviewing their SLA. Which THREE metrics are most important for assessing the provider's reliability and accountability? (Choose three.)

Select 3 answers
A.Number of data center employees
B.Frequency of performance reporting
C.Service credits or compensation for downtime
D.Provider's stock price
E.Monthly uptime percentage guarantee
AnswersB, C, E

Reporting frequency determines how quickly the consumer detects SLA breaches and holds the provider accountable. Without regular performance data, uptime guarantees and credit mechanisms cannot be verified, so this metric underpins the reliability assessment the stem requires.

Why this answer

Option B (Frequency of performance reporting) is correct because an SLA's reporting cadence determines how often the provider must disclose measured performance against targets, giving the customer the visibility needed to verify reliability and hold the provider accountable. Option C (Service credits or compensation for downtime) is correct because financial remedies such as service credits are the primary contractual enforcement mechanism that makes the provider accountable when availability commitments are missed. Option E (Monthly uptime percentage guarantee) is correct because the uptime percentage (for example, 99.9% or 99.95%) is the core quantitative reliability commitment against which actual availability is measured.

Option A (Number of data center employees) does not belong because headcount is not a defined SLA reliability or accountability metric and does not reflect service availability. Option D (Provider's stock price) does not belong because stock price is a financial-market indicator unrelated to the contractual service levels in an SLA.

20
Multi-Selecthard

A cloud security architect is drafting design requirements for storing regulated data in a public cloud IaaS environment. The requirements must address the risks introduced by resource pooling and multi-tenancy. Which TWO of the following design controls directly mitigate multi-tenancy risks in this environment? (Choose two.)

Select 2 answers
A.Require strong workload isolation using virtual networks, security groups, and separate tenant identities
B.Rely on the provider's published service-level agreement to guarantee that tenants never share a physical host
C.Disable all provider-side logging so that telemetry from one tenant cannot be aggregated with another tenant's records
D.Enforce cryptographic isolation of data at rest with tenant-managed keys held outside the provider's control
E.Move the regulated data into the provider's object storage with default provider-managed encryption only
AnswersA, D

Logical segmentation through virtual private networks, security groups, and distinct identity domains keeps one tenant's workloads from reaching another's even when they share physical infrastructure. These controls constrain east-west traffic and administrative reachability, which are the primary paths exploited when isolation is weak. They are standard, effective mitigations for the risks introduced by pooled multi-tenant compute and network resources.

Why this answer

Resource pooling means physical infrastructure is shared, so mitigations must either make the data unreadable to anyone outside the tenant or make the logical boundaries between tenants enforceable and auditable. Externally held encryption keys protect confidentiality even if a boundary fails, and virtual network segmentation with distinct identities constrains reachability. Contractual guarantees, disabled logging, and default provider-managed encryption do not change the underlying sharing risk.

Exam trap

The trap here is accepting a provider guarantee or default encryption as sufficient isolation, when multi-tenancy risk must be mitigated by controls the tenant actually enforces.

21
MCQmedium

A cloud security architect is evaluating a CSP for a financial services client. Which of the following audit reports would provide the most comprehensive assurance regarding the CSP's controls over security, availability, processing integrity, confidentiality, and privacy?

A.PCI DSS Attestation of Compliance
B.SOC 2 Type II
C.SOC 1 Type II
D.ISO 27001 certification
AnswerB

SOC 2 Type II reports on the design and operating effectiveness of controls across security, availability, processing integrity, confidentiality and privacy over an audit period. This matches the stem's five trust services criteria, unlike point-in-time reports.

Why this answer

SOC 2 Type II is specifically designed to provide assurance over security, availability, processing integrity, confidentiality, and privacy (the Trust Services Criteria). It includes an independent auditor's opinion on the effectiveness of controls over a period. This makes it the most comprehensive for the listed areas.

Exam trap

CCSP often tests the distinction between SOC 2 and ISO 27001; candidates might think ISO 27001 certification covers all five trust principles, but SOC 2 Type II is specifically designed for that comprehensive assurance.

How to eliminate wrong answers

Option A is wrong because PCI DSS AoC focuses only on payment card data security, not the broader trust principles. Option C is wrong because SOC 1 Type II is for financial reporting controls (ICFR), not security, availability, etc. Option D is wrong because ISO 27001 certification covers information security management, but it does not specifically address availability, processing integrity, confidentiality, and privacy in the same comprehensive audit report as SOC 2.

22
Multi-Selectmedium

A cloud security manager is evaluating the security responsibilities of the cloud provider and the cloud consumer under the shared responsibility model for a PaaS deployment. Which TWO of the following are typically the responsibility of the cloud consumer? (Choose two.)

Select 2 answers
A.Managing the physical security of data centers
B.Securing the hypervisor and virtualization layer
C.Patching the underlying operating system and runtime
D.Managing user identities and access within the application
E.Configuring application-level security controls
AnswersD, E

The consumer is responsible for managing user identities and access within their application, including creating user accounts, assigning roles, and enforcing least privilege. While the provider may offer identity services, the consumer must configure and manage them for their specific application. This is a key consumer responsibility in PaaS.

Why this answer

In a PaaS model, the cloud provider manages the underlying infrastructure, including servers, operating systems, and runtime environments, while the consumer is responsible for the security of their applications and data. This includes configuring application-level security controls and managing user identities and access within the application. These two areas fall under the consumer's control and are critical for protecting the application from threats.

Exam trap

The trap here is assuming that because the provider manages the platform, the consumer has no security responsibilities, or confusing infrastructure-level responsibilities with application-level ones.

23
Multi-Selectmedium

An enterprise is evaluating whether to move a legacy customer relationship management system to a cloud provider. The security architect must assess the provider's ability to meet the enterprise's control requirements before signing. Which TWO artifacts or activities BEST provide direct evidence of the provider's security control environment? (Choose two.)

Select 2 answers
A.A current independent third-party audit report covering the relevant trust services criteria
B.The provider's public marketing brochure describing its security posture
C.A customer reference call with another organization of similar size in the same industry
D.A completed security questionnaire returned by the provider, with supporting documentation reviewed in a follow-up session
E.The provider's standard terms of service and acceptable use policy
AnswersA, D

An independent audit report, such as a SOC 2 report, is produced by a qualified auditor and describes the design and operating effectiveness of controls against defined criteria over a specific period. It gives the architect evidence that controls exist and were tested, along with any exceptions noted. This is direct, verifiable evidence rather than a self-declaration, making it one of the strongest artifacts for pre-contract assessment.

Why this answer

Direct evidence comes from independent testing and from a structured, documented assessment conducted by the enterprise itself. An independent third-party audit report covers defined criteria over a stated period and discloses exceptions, while a framework-mapped questionnaire reviewed with the provider turns vague assurances into specific, verifiable answers. Marketing brochures, terms of service, and reference calls may inform the decision, but they do not establish that the provider's controls are designed and operating effectively.

Exam trap

The trap here is accepting provider-authored assurances or peer anecdotes as control evidence instead of independently tested reports and documented assessment results.

24
MCQhard

A healthcare organization is designing a cloud solution to store and process electronic protected health information (ePHI). The organization must comply with HIPAA and wants to ensure that the cloud service provider (CSP) meets the necessary security and privacy requirements. The organization is evaluating a CSP that offers a Business Associate Agreement (BAA). Which of the following is the MOST critical factor to verify before signing the BAA?

A.The CSP's BAA includes a clause allowing the CSP to use ePHI for its own purposes.
B.The CSP's data center locations are within the United States.
C.The CSP has implemented appropriate administrative, physical, and technical safeguards to protect ePHI.
D.The CSP offers a 99.999% uptime service level agreement (SLA).
AnswerC

Under HIPAA, a covered entity must ensure that its business associates, including CSPs, implement appropriate safeguards to protect ePHI. The BAA itself is a contractual requirement, but the most critical factor is verifying that the CSP actually has the necessary administrative, physical, and technical safeguards in place. This includes access controls, encryption, audit controls, and integrity controls, which are essential to comply with the HIPAA Security Rule.

Why this answer

The HIPAA Security Rule requires covered entities and their business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Before signing a BAA, the healthcare organization must verify that the CSP has these safeguards in place. While data residency, contractual clauses, and SLAs are relevant, they do not replace the need for comprehensive security controls.

Exam trap

The trap here is focusing on the BAA as a document rather than on the underlying security controls. A BAA is necessary but not sufficient; the CSP must actually implement the required safeguards, and the organization must verify this through audits or certifications.

25
MCQhard

A government agency is evaluating a cloud deployment model where several agencies with similar missions and compliance obligations will jointly use a cloud environment governed by a shared policy framework. Each agency will retain independent control over its own data and security configurations. Which cloud deployment model does this describe?

A.Hybrid cloud
B.Community cloud
C.Private cloud
D.Public cloud
AnswerB

A community cloud is provisioned for exclusive use by a specific community of consumers from organizations that share common concerns such as mission, security requirements, policy, and compliance considerations. The scenario explicitly describes multiple agencies with similar missions and obligations jointly using a governed environment while retaining control over their own data, which is the textbook community cloud arrangement.

Why this answer

The community cloud model is defined by exclusive use among a group of organizations sharing common mission, security, policy, and compliance interests. Because several agencies jointly consume the environment under a shared governance framework while each controls its own data, this matches the community cloud definition precisely rather than single-tenant private, open public, or cross-model hybrid arrangements.

Exam trap

The trap here is confusing a community cloud with a private cloud simply because access is restricted, when the distinguishing factor is that multiple independent organizations share the environment under common governance.

26
MCQmedium

A media production company stores and edits large video files on-premises. During peak project periods, editors need to temporarily consume extra compute and storage, but the company wants to keep its existing private cloud and avoid rebuilding workflows. The company wants a solution that lets the private cloud seamlessly use public cloud resources for these bursts without changing how editors access the files. Which cloud deployment model BEST meets this requirement?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Community cloud
AnswerA

A hybrid cloud combines a private cloud with public cloud services and enables workloads to move or burst between them. Here, the private cloud can remain the primary editing environment while public cloud resources absorb peak compute and storage demands, which matches the requirement to keep existing workflows and avoid a full migration.

Why this answer

A hybrid cloud is designed to integrate a private cloud with public cloud services so workloads can move or burst between them. Because the company wants to retain its private editing workflows while temporarily using public resources during peaks, the hybrid model provides the required elasticity without forcing a full migration or redesign.

Exam trap

The trap here is assuming that any use of public cloud capacity automatically makes the deployment a public cloud, when the defining factor is the integrated combination of private and public environments.

27
Multi-Selectmedium

An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)

Select 3 answers
A.Dedicated security team for each environment
B.Unified identity and access management (IAM)
C.Consistent network segmentation and firewall rules
D.Harmonized data encryption and key management
E.Different encryption standards for public and private clouds
AnswersB, C, D

A single identity plane spanning on-premises and cloud lets one directory govern authentication and authorisation everywhere. Microsoft Entra ID provides this, satisfying the hybrid requirement for consistent access control rather than duplicated, divergent credential stores.

Why this answer

Unified IAM (B) is vital because a hybrid cloud requires a single, consistent authentication and authorization model—using standards like SAML, OAuth 2.0, or OIDC and centralized directory services—so that identities and permissions behave identically across on-premises and cloud environments rather than fragmenting into separate trust domains. Consistent network segmentation and firewall rules (C) are essential because traffic flows between private and public environments must be governed by the same security zones, ACLs, and microsegmentation policies; otherwise lateral movement and misconfigured cross-cloud connectivity create exploitable gaps. Harmonized data encryption and key management (D) is critical because data moving between or stored across environments must use compatible algorithms and centrally governed keys (e.g., via a KMS or HSM with consistent rotation and access policies) to avoid weak links and unmanageable key sprawl.

Option A is not required—separate security teams per environment actually undermine consistency by creating divergent policies and fragmented accountability, whereas a unified governance model with shared standards is preferred. Option E is incorrect because using different encryption standards for public versus private clouds introduces interoperability, compliance, and key-management problems; encryption should be harmonized, not differentiated by environment.

Exam trap

CCSP often tests the misconception that hybrid cloud security is best achieved by giving each environment its own dedicated team and tailored controls, when the exam's correct answer always favors unified, consistent controls across environments.

28
MCQmedium

Which cloud design principle ensures that resources can be dynamically adjusted to meet changing demand, often using auto-scaling groups?

A.Elasticity
B.Resource pooling
C.Resiliency
D.Measured service
AnswerA

Elasticity directly satisfies the changing-demand constraint by automatically provisioning and deprovisioning resources through auto-scaling groups, matching capacity to real-time workload. Unlike scalability, which addresses growth in fixed increments, elasticity handles fluctuating demand dynamically, including scale-in, making it the precise principle described in the stem.

Why this answer

Elasticity is the cloud design principle that allows resources to be automatically and dynamically scaled up or down to match changing demand, typically implemented via auto-scaling groups, horizontal pod autoscalers, or serverless concurrency. It is what lets a workload add capacity during peak load and release it during idle periods, optimizing both performance and cost. Auto-scaling groups are the canonical implementation of elasticity on IaaS platforms.

Exam trap

The trap here is conflating elasticity with scalability or resiliency; candidates pick 'resiliency' because auto-scaling 'sounds like' high availability, but the question's keyword is dynamic adjustment to demand.

How to eliminate wrong answers

Option B is wrong because resource pooling refers to the multi-tenant model where a provider serves many consumers from shared physical resources (compute, storage, network), not to dynamic scaling. Option C is wrong because resiliency is the ability to withstand and recover from failures (redundancy, failover, multi-AZ), which is about availability, not demand-driven scaling. Option D is wrong because measured service (metering) is the pay-per-use billing model that tracks consumption, not the mechanism that adjusts capacity.

29
MCQhard

A cloud architect is designing a solution that must ensure data isolation between tenants in a multi-tenant environment. The architect decides to use a virtual private cloud (VPC) per tenant. Which of the following is the PRIMARY security benefit of this approach?

A.It provides dedicated physical hardware for each tenant.
B.It automatically encrypts all data at rest for each tenant.
C.It guarantees compliance with data residency requirements.
D.It ensures that each tenant's network traffic is isolated from other tenants.
AnswerD

A VPC enables logical isolation of network traffic at the virtual network layer. Each tenant's resources are placed in separate subnets with their own routing and security group rules, preventing unauthorized access between tenants. This is a fundamental security control in multi-tenant cloud environments, as it reduces the risk of lateral movement and data leakage.

Why this answer

Using a VPC per tenant provides network-level isolation, which is critical in multi-tenant environments to prevent cross-tenant traffic and unauthorized access. Each VPC acts as a virtual network boundary, with its own IP range, subnets, route tables, and security groups. This logical separation helps enforce security policies and reduces the attack surface, making it the primary security benefit.

Exam trap

The trap here is conflating network isolation with other security controls like encryption or physical separation, and assuming that a VPC automatically provides those benefits.

30
MCQmedium

Which design principle is most directly aimed at avoiding vendor lock-in and ensuring that workloads can be moved between cloud providers with minimal effort?

A.Portability
B.Reversibility
C.Elasticity
D.Multitenancy isolation
AnswerA

Portability is the design principle that keeps workloads free of provider-specific dependencies, allowing migration between clouds with minimal rework. It directly addresses vendor lock-in by requiring portable formats, APIs and configurations, so the stem's movement requirement is met.

Why this answer

Portability is the design principle specifically concerned with avoiding vendor lock-in by ensuring workloads, data, and configurations can be moved between cloud providers with minimal rework. It drives the use of open standards, containerization, and abstraction layers so that an application is not tied to proprietary APIs or services. Reversibility is related but focuses on the ability to exit a provider and bring data back, whereas portability is about the ability to move and run elsewhere.

Exam trap

The trap here is confusing portability with reversibility — both relate to avoiding lock-in, but portability is about moving workloads to another provider, while reversibility is about exiting and recovering data from the current provider.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to terminate a cloud relationship and retrieve data, not the ability to run workloads on another provider with minimal effort. Option C is wrong because elasticity is the ability to automatically scale resources up and down based on demand — it has nothing to do with vendor lock-in. Option D is wrong because multitenancy isolation is about separating tenant data and workloads in a shared environment, not about moving workloads between providers.

31
MCQeasy

A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?

A.Public cloud
B.Hybrid cloud
C.Community cloud
D.Private cloud
AnswerD

A private cloud provides infrastructure dedicated solely to one organisation, with no shared compute, storage or network resources. Public, hybrid and community models all involve some shared infrastructure, so only the private deployment model satisfies the no-sharing constraint.

Why this answer

Private cloud is dedicated to a single organization, providing exclusive use of infrastructure. Public cloud is shared, community is shared by multiple organizations with common interests, and hybrid combines models.

32
Multi-Selecthard

A company is evaluating cloud providers for a critical workload and requires high availability, disaster recovery, and portability. Which THREE factors should the company prioritize in the provider evaluation?

Select 3 answers
A.Support for open APIs and industry standards
B.Availability of independent audit reports (e.g., SOC 2, ISO 27001)
C.Provider's customer support tiers
D.SLA guarantees for uptime and availability
E.Number of data center locations
AnswersA, B, D

Support for open APIs and industry standards directly satisfies the portability constraint by preventing vendor lock-in, letting the workload migrate between providers. Standardised interfaces also underpin resilient multi-provider architectures, so this factor addresses both the portability and high-availability requirements rather than only one.

Why this answer

Option A is correct because support for open APIs and industry standards directly enables portability, allowing the company to avoid vendor lock-in and migrate or integrate workloads across providers using well-defined interfaces. Option B is correct because independent audit reports such as SOC 2 and ISO 27001 provide verifiable assurance that the provider's security, availability, and operational controls meet recognized compliance frameworks, which is essential for a critical workload. Option D is correct because SLA guarantees for uptime and availability define the provider's contractual commitment to high availability and provide measurable remedies if service levels are missed, directly supporting the HA/DR requirement.

Option C is not a primary evaluation factor here because customer support tiers affect responsiveness and service experience but do not by themselves deliver high availability, disaster recovery, or portability. Option E is also not a primary factor because the number of data center locations alone does not guarantee HA/DR or portability; what matters is how those locations are architected, replicated, and exposed through standards and SLAs.

33
Multi-Selecthard

A cloud architect is designing a multi-tier application that will be deployed in a public cloud. The application must meet strict security and compliance requirements, including data isolation, network segmentation, and encryption of data at rest and in transit. The architect is considering using a virtual private cloud (VPC) and must ensure that the design aligns with the cloud shared responsibility model. Which TWO of the following are the cloud customer's responsibilities under the shared responsibility model? (Choose two.)

Select 2 answers
A.Ensuring the physical network infrastructure is redundant and fault-tolerant.
B.Managing the physical security of the data center where the application is hosted.
C.Encrypting application data at rest using customer-managed keys.
D.Configuring security groups and network ACLs to control traffic to and from the application instances.
E.Patching the hypervisor and underlying host operating system.
AnswersC, D

The customer is responsible for encrypting their data at rest, including choosing and managing encryption keys. While the cloud provider may offer encryption capabilities and key management services, the customer must configure and manage the encryption of their own data. This includes using customer-managed keys (CMKs) to maintain control over access to the data.

Why this answer

Under the shared responsibility model for IaaS, the customer is responsible for security in the cloud, which includes configuring network controls (security groups, network ACLs) and encrypting data at rest with customer-managed keys. The provider is responsible for security of the cloud, including physical security, hypervisor patching, and physical network redundancy. Therefore, the customer's responsibilities are configuring security groups and network ACLs, and encrypting application data at rest.

Exam trap

The trap here is confusing the provider's responsibility for physical security and hypervisor management with the customer's responsibility for securing their own data and network configurations. Many candidates incorrectly assume the provider handles all aspects of security, including data encryption.

34
MCQmedium

A media production company wants to use a public cloud for rendering video but must retain full control over the guest OS, patching, and runtime configuration. The company does not want to manage physical hardware or hypervisors. Which cloud service model BEST meets these requirements?

A.Function as a Service (FaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Software as a Service (SaaS)
AnswerC

IaaS provides virtualized compute, storage, and networking while the provider manages the physical hosts and hypervisor. The customer retains control of the guest operating system, middleware, and applications, which aligns with the need to control patching and runtime configuration. It also avoids hardware and hypervisor management, exactly matching the stated requirements.

Why this answer

IaaS is the only model that gives the customer control over the guest operating system and runtime while the provider manages the physical infrastructure and hypervisor. PaaS, SaaS, and FaaS abstract away the OS layer, removing the control the media company needs. The scenario explicitly requires retaining patching and runtime configuration, which maps directly to IaaS responsibilities.

Exam trap

The trap here is assuming that any cloud model removing hardware management also permits guest OS control, when only IaaS preserves that layer for the customer.

35
MCQeasy

In the shared responsibility model for public cloud, which of the following is typically the responsibility of the cloud customer when using IaaS?

A.Network firewall configuration at the hypervisor level
B.Physical security of data centers
C.Patch management of the guest operating system
D.Storage device maintenance
AnswerC

In IaaS the provider secures the physical hosts, network, and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching that guest OS, including its installed software and security updates, therefore falls to the customer.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical infrastructure, hypervisor, and network fabric, while the customer is responsible for everything from the guest OS upward — including OS patching, middleware, runtime, applications, and data. Patch management of the guest operating system (C) is therefore squarely the customer's duty. This is a defining characteristic of IaaS versus PaaS or SaaS, where the provider assumes more of the stack.

Exam trap

CCSP often tests the boundary between provider and customer responsibilities; the trap is assuming the provider patches everything, when in IaaS the guest OS is explicitly the customer's job.

How to eliminate wrong answers

Option A is wrong because hypervisor-level network firewall configuration is part of the provider's virtualization and network infrastructure layer, not the customer's responsibility in IaaS. Option B is wrong because physical security of data centers is always the cloud provider's responsibility under every service model. Option D is wrong because storage device maintenance (hardware, firmware, disk replacement) is handled by the provider as part of the physical infrastructure layer.

36
Multi-Selectmedium

A company is adopting a hybrid cloud strategy. Which TWO security considerations are most critical for maintaining a consistent security posture across environments? (Choose two.)

Select 2 answers
A.Establishing consistent network security policies (e.g., firewall rules)
B.Relying solely on perimeter security
C.Deploying separate security teams for each environment
D.Implementing identity federation for single sign-on
E.Using different encryption keys for each environment
AnswersA, D

Hybrid cloud spans on-premises and provider networks, so inconsistent firewall rules create gaps between environments. Uniform network security policies enforce one traffic-filtering baseline across both sides, directly satisfying the stem's demand for a consistent security posture.

Why this answer

Option A is correct because consistent network security policies such as firewall rules, security groups, and ACLs ensure that traffic controls are enforced uniformly across on-premises and cloud environments, preventing gaps that attackers could exploit when workloads span both. Option D is correct because identity federation for single sign-on (e.g., SAML 2.0 or OIDC with a central IdP like Entra ID or Okta) provides a unified authentication and authorization model, so users and services have consistent identities and access rights regardless of environment. Option B is incorrect because relying solely on perimeter security fails in hybrid cloud, where assets sit outside a single network boundary and zero-trust, defense-in-depth controls are required.

Option C is incorrect because separate security teams per environment create inconsistent policies, duplicated effort, and coordination gaps rather than a unified posture. Option E is incorrect because using different encryption keys per environment is not inherently a consistency requirement; key management should follow a unified governance model (e.g., centralized KMS/HSM with proper key rotation and separation), not simply differ by environment.

Exam trap

CCSP often tests the misconception that perimeter security or environment-specific teams/keys provide consistency, when in fact hybrid cloud consistency hinges on unified policy and federated identity.

37
MCQmedium

A media company runs a video-transcoding workload on a public cloud IaaS platform. The workload is stateless, tolerant of interruption, and must complete within a 6-hour window at the lowest possible compute cost. The company's architects propose using a cloud service that provisions spare capacity at a significant discount but can reclaim it with a two-minute notice. Which cloud deployment and service model does this describe?

A.Reserved instances within a community cloud
B.Dedicated hosts within a private cloud
C.Spot instances within a public cloud
D.On-demand instances within a hybrid cloud
AnswerC

Spot instances (also called spot VMs or preemptible VMs) let a consumer bid on a provider's unused capacity at steep discounts, and the provider can reclaim that capacity with short notice, often around two minutes. Stateless, interruption-tolerant batch work such as video transcoding is the canonical fit, and the reclaimed capacity directly explains the lowest-cost requirement in this scenario.

Why this answer

The workload is stateless, tolerant of interruption, and cost-sensitive, which maps precisely to spare-capacity compute sold at a discount with short-notice reclamation. Committed-term reservations, physically isolated hosts, and full-price on-demand capacity all fail at least one stated constraint, either cost, availability guarantees, or the eviction behavior the architects are designing around.

Exam trap

The trap here is assuming any discounted compute purchase is equivalent, when only spare-capacity instances carry the provider-initiated reclamation with short notice that this workload is built to tolerate.

38
MCQmedium

A cloud architect is documenting the essential characteristics that distinguish a cloud service from traditional hosting for an internal design review. The architect must list the characteristics defined in the widely used cloud reference architecture. Which of the following is one of those essential characteristics?

A.Guaranteed data residency in a single jurisdiction
B.Perpetual license ownership of the provider's software
C.Rapid elasticity and measured service
D.Mandatory single-tenancy of every physical host
AnswerC

Rapid elasticity describes capabilities that appear unlimited and can be scaled out and back in quickly, while measured service means resource usage is monitored, controlled, and reported transparently to both provider and consumer. Both appear in the standard set of essential cloud characteristics. They distinguish cloud from fixed hosting because capacity flexes with demand and consumption is metered for billing and governance.

Why this answer

The essential characteristics describe on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. Rapid elasticity and measured service together capture how capacity flexes with demand and how consumption is metered and reported, which are definitional traits. Residency guarantees, single-tenancy mandates, and perpetual licensing are commercial or deployment choices, not defining cloud characteristics.

Exam trap

The trap here is mixing commercial terms such as residency guarantees or perpetual licensing into the architectural definition of what makes a service cloud.

39
MCQhard

A cloud customer is evaluating a provider's service level agreement (SLA) that guarantees 99.99% availability. What is the maximum allowable downtime per year (in minutes) before the SLA is violated?

A.8.76 hours
B.52.56 minutes
C.5.26 minutes
D.87.6 hours
AnswerB

A 99.99% availability guarantee permits 0.01% annual downtime. Applied to 525,600 minutes per year, that equals 52.56 minutes, the exact threshold the SLA specifies. Any outage exceeding this figure breaches the agreement, making it the maximum allowable downtime the stem requests.

Why this answer

An SLA of 99.99% availability allows 0.01% downtime per year. A year has 365 days × 24 hours × 60 minutes = 525,600 minutes. 0.01% of 525,600 is 52.56 minutes, so the maximum allowable downtime is 52.56 minutes per year. This is the correct calculation.

Exam trap

CCSP often tests the conversion between availability percentages and actual downtime, and candidates may confuse the number of nines (e.g., 99.9% vs 99.99%) or miscompute the minutes per year.

How to eliminate wrong answers

Option A is wrong because 8.76 hours corresponds to 99.9% availability (0.1% downtime), not 99.99%. Option C is wrong because 5.26 minutes corresponds to 99.999% availability (0.001% downtime). Option D is wrong because 87.6 hours corresponds to 99% availability (1% downtime).

40
MCQhard

A government agency is comparing cloud providers and must prove to auditors that its workloads will remain available and recoverable during a regional provider outage. The agency wants an objective, contractual commitment about the percentage of time a service will be operational, plus a documented financial remedy if the provider misses that target. Which provider artifact should the agency rely on FIRST?

A.The provider's service level agreement
B.The provider's architecture whitepaper
C.The provider's independent audit report
D.The provider's disaster recovery test summary
AnswerA

A service level agreement states the measurable service levels the provider commits to, such as a monthly uptime percentage, and defines the remedies, typically service credits, when those levels are missed. It is the contractual artifact that turns an availability expectation into an enforceable commitment. Auditors can examine the stated targets and the remedy terms directly, which is exactly what the agency needs.

Why this answer

The agency needs a measurable availability commitment plus a defined remedy, and that is precisely what a service level agreement provides. It sets the uptime percentage, the measurement window, exclusions, and the service credits owed when targets are missed. Audit reports, disaster recovery test summaries, and architecture whitepapers are useful evidence about controls and design, but none of them creates an enforceable service commitment with compensation terms.

Exam trap

The trap here is equating a favorable audit report or architecture document with a contractual availability guarantee, when only the service level agreement sets measurable targets and remedies.

41
MCQeasy

Which cloud service model allows customers to manage only their data and user access, while the provider manages everything else including the infrastructure, operating system, and applications?

A.SaaS
B.IaaS
C.CaaS
D.PaaS
AnswerA

SaaS delivers a complete provider-managed application stack, so the customer manages only its data and user access while the provider handles infrastructure, operating system and application. This exactly satisfies the stem's stated division of responsibility.

Why this answer

SaaS (Software as a Service) is the cloud service model where the provider manages the entire stack — infrastructure, operating system, runtime, middleware, and the application itself — leaving the customer responsible only for their data and user access management. Examples include Microsoft 365, Salesforce, and Google Workspace, where the customer configures users and manages data but never touches the underlying platform.

Exam trap

CCSP often tests the boundary between SaaS and PaaS by emphasizing who manages the application — in SaaS the provider manages the app, while in PaaS the customer deploys their own app on a managed platform.

How to eliminate wrong answers

Option B is wrong because IaaS (Infrastructure as a Service) gives the customer control over the operating system, storage, and deployed applications, with the provider managing only the virtualization and physical infrastructure — the customer manages far more than just data and user access. Option C is wrong because CaaS (Containers as a Service) provides a container orchestration platform where the customer still manages container images, orchestration configuration, and often the runtime — not just data and user access. Option D is wrong because PaaS (Platform as a Service) provides a managed runtime and development platform, but the customer still manages their application code, configuration, and sometimes middleware — more than just data and user access.

42
MCQmedium

A company uses a hybrid cloud model where sensitive data resides in a private cloud, while compute-intensive analytics run in a public cloud using anonymized data. What is the primary security consideration for this architecture?

A.Using the same hypervisor in both clouds
B.Implementing network segmentation only in the public cloud
C.Maintaining consistent security policies and secure connectivity between environments
D.Ensuring the public cloud provider has SOC 2 certification
AnswerC

Sensitive data stays private while anonymised analytics run publicly, so the split architecture's core risk is drift between the two domains. Consistent security policies plus secure connectivity (VPN or dedicated link) prevent the public environment becoming a weaker path into private data, satisfying the hybrid model's boundary constraint.

Why this answer

In hybrid cloud, consistent security policies must apply across both environments, and secure connectivity (e.g., VPN or dedicated connection) is essential to protect data in transit and prevent leakage.

43
MCQmedium

Which of the following is a key benefit of using a hybrid cloud deployment model?

A.Ability to keep sensitive data on-premises while leveraging public cloud for less sensitive workloads
B.Complete isolation from public networks
C.Single vendor management
D.Elimination of shared responsibility
AnswerA

Hybrid cloud combines distinct on-premises and public cloud environments bound by technology enabling data and application portability. This lets the organisation retain sensitive data on its private infrastructure while running less sensitive workloads cost-effectively in the public cloud, satisfying both control and scalability needs.

Why this answer

A key benefit of hybrid cloud is the ability to keep sensitive data on-premises while leveraging public cloud for less sensitive workloads, thus meeting compliance and security requirements while gaining cloud scalability. This flexibility is a primary driver for hybrid adoption.

Exam trap

CCSP often tests the misconception that hybrid cloud eliminates shared responsibility or provides complete isolation; candidates might confuse hybrid cloud with private cloud.

How to eliminate wrong answers

Option B is wrong because complete isolation from public networks is not a benefit of hybrid cloud; hybrid cloud by definition involves some connectivity to public cloud. Option C is wrong because hybrid cloud often involves multiple vendors, not single vendor management. Option D is wrong because hybrid cloud does not eliminate shared responsibility; the organization still retains responsibility for on-premises and some aspects of cloud security.

44
MCQhard

A cloud architect is designing a system that must survive the failure of an entire cloud provider region. The application uses a relational database and object storage. Which design approach BEST achieves regional fault tolerance while minimizing data loss and operational complexity?

A.Deploy the application in a single region with a multi-master database cluster spanning three availability zones and global load balancing.
B.Deploy the application in two availability zones within a single region and rely on the provider's managed backup service for the database.
C.Deploy the application in two regions using synchronous database replication and a single object storage bucket with cross-region access.
D.Deploy the application in two regions with asynchronous database replication and cross-region replication for object storage, then use DNS failover to redirect traffic.
AnswerD

This design places the application in two independent regions, replicates the database asynchronously to bound latency impact, replicates object storage across regions, and uses DNS failover to shift traffic. It directly addresses a full region outage while keeping operational complexity manageable compared with active-active multi-master database designs.

Why this answer

Surviving a full region failure requires resources and data in at least two independent regions. Asynchronous database replication avoids the latency and availability penalties of synchronous cross-region writes, cross-region object storage replication protects unstructured data, and DNS failover provides a practical traffic redirection mechanism with acceptable recovery time objectives.

Exam trap

The trap here is treating multi-availability-zone redundancy inside one region as equivalent to regional fault tolerance.

45
MCQmedium

A multinational retailer is selecting a cloud deployment model for a new inventory system. The system must be accessible to stores in several countries, must scale rapidly during seasonal promotions, and must be managed by a third-party provider. The retailer does not want to own or maintain the underlying infrastructure. Which cloud deployment model BEST fits these requirements?

A.Hybrid cloud
B.Community cloud
C.Public cloud
D.Private cloud
AnswerC

A public cloud is owned and operated by a third-party provider and offers rapid elasticity and broad geographic reach. The retailer can deploy the inventory system without owning infrastructure and scale during seasonal promotions, which directly satisfies the stated requirements for global access, elasticity, and outsourced management.

Why this answer

A public cloud is provider-owned and offers on-demand scaling and global availability, which matches the retailer's need to avoid infrastructure ownership while supporting stores in multiple countries and handling seasonal demand spikes. The other models either require dedicated infrastructure, shared governance, or unnecessary private integration.

Exam trap

The trap here is assuming that global reach or third-party management automatically implies hybrid cloud, when a public cloud alone already provides those characteristics.

46
MCQeasy

A small business wants to move its email and productivity suite to a cloud service where the provider manages the application, runtime, and underlying infrastructure, and users access the software through a browser. Which cloud service model is being described?

A.Function as a Service (FaaS)
B.Software as a Service (SaaS)
C.Platform as a Service (PaaS)
D.Infrastructure as a Service (IaaS)
AnswerB

SaaS delivers a complete application managed by the provider, including the runtime and infrastructure, and users access it through a browser or thin client. This matches the scenario where the business consumes email and productivity software without managing any underlying layers, leaving only limited user-specific configuration to the customer.

Why this answer

In SaaS, the provider manages the application, runtime, middleware, operating system, and infrastructure, while the customer consumes the software, often through a browser. Email and productivity suites delivered this way fit the SaaS model precisely, with the customer retaining only limited configuration and user management responsibilities.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when the distinguishing factor is who manages the application layer.

47
MCQmedium

Which of the following is a key benefit of using containers, such as Docker, in a cloud environment to achieve portability?

A.Containers package applications with dependencies to run consistently across environments
B.Containers are always stateless
C.Containers require a specific hypervisor to run
D.Containers provide hardware-level virtualization
AnswerA

Containers bundle the application with its libraries and dependencies into a single image, so the same artefact runs identically on any container host. This dependency packaging, rather than hypervisor abstraction, delivers the portability across cloud environments.

Why this answer

Containers bundle the application code together with its libraries, runtime, and configuration into a single immutable image, so the same image runs identically on a developer laptop, on-premises servers, or any cloud VM/container service. This decoupling from the underlying host OS and infrastructure is precisely what delivers portability across cloud environments.

Exam trap

The trap here is conflating containers with virtual machines — candidates who remember 'virtualization' from VM study material may pick hardware-level virtualization (D) or hypervisor dependency (C), missing that containers virtualize at the OS layer and are defined by packaging dependencies for consistency.

How to eliminate wrong answers

Option B is wrong because containers are not inherently stateless — statefulness depends on how the application is written and whether it uses persistent volumes; many stateful workloads (databases, caches) run in containers. Option C is wrong because containers share the host OS kernel and do not require a hypervisor; a hypervisor is used by virtual machines, not by the container runtime itself. Option D is wrong because containers provide OS-level (process) virtualization, not hardware-level virtualization — hardware virtualization is the domain of hypervisors and VMs.

48
MCQeasy

In the NIST SP 800-145 definition, which deployment model is described as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerA

NIST SP 800-145 defines the private cloud as infrastructure provisioned for exclusive use by a single organisation comprising multiple consumers, whether business units or employees. Exclusivity plus multi-consumer tenancy within one organisation is the precise axis separating it from public, community and hybrid models.

Why this answer

NIST SP 800-145 defines the private cloud deployment model as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). The key characteristic is exclusive use by one organization, whether owned/operated by the organization or a third party, and whether on-premises or off-premises.

Exam trap

CCSP often tests the precise NIST wording — candidates confuse 'single organization comprising multiple consumers' (private) with 'community of consumers from organizations that share concerns' (community).

How to eliminate wrong answers

Option B is wrong because the public cloud is provisioned for open use by the general public and is owned by a cloud provider — it is not exclusive to a single organization. Option C is wrong because the community cloud is provisioned for exclusive use by a specific community of consumers from organizations that share concerns (e.g., mission, security requirements, policy) — it is not a single organization. Option D is wrong because the hybrid cloud is a composition of two or more distinct cloud infrastructures (private, community, or public) bound by technology enabling data and application portability — it is not defined as exclusive use by a single organization.

49
MCQmedium

A media company runs a video transcoding workflow on a public cloud. Jobs arrive unpredictably and must be processed within minutes, but the company wants to minimize cost by using spare capacity that can be reclaimed when demand for full-price capacity rises. The jobs are checkpointed every 30 seconds and can resume on a different host. Which cloud service model and purchasing approach BEST fits this requirement?

A.Platform as a Service with a committed use discount
B.Infrastructure as a Service with dedicated hosts
C.Infrastructure as a Service with spot instances
D.Software as a Service with a per-seat subscription
AnswerC

Spot instances sell unused provider capacity at a steep discount and can be reclaimed with a short notice period, which matches the requirement to minimize cost using spare capacity. Because the transcoding jobs checkpoint every 30 seconds and can resume on another host, interruption is tolerable. IaaS also gives the team full control over the runtime needed to install and tune the transcoding software.

Why this answer

The workload is interruption-tolerant because it checkpoints frequently and can resume elsewhere, which is exactly the profile that reclaimable spare-capacity pricing is built for. Using infrastructure as a service preserves control over the transcoding runtime while allowing the team to bid on spare capacity and cut cost. Committed discounts, per-seat subscriptions, and dedicated hosts all price or isolate capacity in ways that do not match unpredictable, bursty batch processing.

Exam trap

The trap here is assuming that any discounted cloud pricing model will reduce cost for bursty work, when committed-use and per-seat models actually require predictable consumption or named users.

50
MCQhard

A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?

A.A virtual private cloud with private subnets and a service endpoint
B.A web application firewall in front of the API gateway
C.A content delivery network with origin shielding
D.A dedicated hardware security module cluster
AnswerA

A virtual private cloud gives the bank a logically isolated network in which it defines its own address ranges, subnets, route tables, and gateways. Private subnets keep the payment API off the public internet while security groups and network ACLs control traffic. A service endpoint lets the VPC reach the provider's object storage over the provider's private backbone instead of the public internet, satisfying the private-connectivity requirement.

Why this answer

The requirement combines network isolation, customer-defined addressing and traffic control, and private access to a provider service. A virtual private cloud supplies the isolated network and its subnets, route tables, and gateways; security groups and network ACLs provide the traffic control; and a service endpoint keeps storage traffic on the provider backbone. Content delivery, web application firewalls, and hardware security modules address latency, application attacks, and key protection, not network isolation.

Exam trap

The trap here is treating a security appliance such as a web application firewall or hardware security module as if it establishes network isolation, when isolation comes from the virtual network construct itself.

51
MCQhard

A cloud customer is reviewing a provider's SOC 2 Type II report. What does this report primarily attest to?

A.The provider's financial controls and accuracy of billing
B.The design and operating effectiveness of controls over a period
C.Compliance with international data protection regulations like GDPR
D.Penetration test results and vulnerability assessments
AnswerB

A SOC 2 Type II report attests to both the suitability of control design and the operating effectiveness of those controls throughout a specified review period. This period-based testing distinguishes it from Type I, which covers design at a single point in time.

Why this answer

A SOC 2 Type II report attests to the design and operating effectiveness of a service organization's controls over a specified period (typically 3–12 months). It goes beyond a Type I report, which only evaluates control design at a point in time, by testing whether controls operated effectively throughout the audit period.

Exam trap

The trap is confusing SOC 2 Type II with SOC 1 (financial controls) or with regulatory compliance attestations like GDPR — candidates must remember that SOC 2 Type II specifically addresses the design and operating effectiveness of controls over a period, based on the AICPA Trust Services Criteria.

How to eliminate wrong answers

Option A is wrong because SOC 2 focuses on security, availability, processing integrity, confidentiality, and privacy — not financial controls or billing accuracy (that would be SOC 1 or financial audits). Option C is wrong because GDPR compliance is a legal/regulatory determination, not what a SOC 2 report attests to; SOC 2 is based on the AICPA Trust Services Criteria, not GDPR. Option D is wrong because penetration test results and vulnerability assessments are separate artifacts; a SOC 2 report may reference them as evidence but does not primarily attest to them.

52
MCQmedium

Which of the following is an example of a cloud interoperability standard that facilitates portability of containerized applications across different cloud environments?

A.SOC 2 Type II
B.CSA STAR
C.ISO 27001
D.Kubernetes
AnswerD

Kubernetes is an open-source container orchestration standard whose portable API and workload definitions let containerised applications move between cloud environments without provider-specific rewriting. That vendor-neutral abstraction directly delivers the portability the stem requires, unlike proprietary platform services.

Why this answer

Kubernetes is an open-source container orchestration platform whose API and manifests (pods, deployments, services) are portable across cloud providers, making it the de facto interoperability standard for containerized workloads. It is governed by the CNCF and implemented by AWS EKS, Azure AKS, GCP GKE, and on-prem distributions, enabling workload portability.

Exam trap

The trap is conflating security/compliance frameworks (SOC 2, ISO 27001, CSA STAR) with technical interoperability standards — candidates who see 'standard' and think 'certification' may pick an audit framework instead of the actual orchestration technology (Kubernetes).

How to eliminate wrong answers

Option A is wrong because SOC 2 Type II is an auditing attestation about a service organization's controls, not a technical interoperability standard for containers. Option B is wrong because CSA STAR is a cloud security assurance program (based on the Cloud Controls Matrix) that assesses provider security posture, not a portability standard. Option C is wrong because ISO 27001 is an information security management system standard — a governance/audit framework, not a container portability specification.

53
MCQeasy

Which NIST-defined cloud characteristic ensures that resources can be scaled up and down rapidly based on demand?

A.Broad network access
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerB

Rapid elasticity is the NIST characteristic permitting capabilities to be provisioned and released elastically, scaling outward and inward commensurate with demand. It directly satisfies the stem's requirement that resources scale up and down rapidly as demand changes.

Why this answer

Rapid elasticity is the NIST-defined essential characteristic that allows cloud resources to be provisioned and released automatically, scaling outward and inward commensurate with demand. It enables the cloud consumer to scale capabilities elastically, often in near real-time, without human intervention. This characteristic directly addresses the ability to scale up and down rapidly based on demand, as stated in the question.

Exam trap

CCSP often tests the confusion between rapid elasticity and resource pooling, as both involve dynamic resource allocation, but only rapid elasticity specifically addresses scaling up and down based on demand.

How to eliminate wrong answers

Option A is wrong because broad network access refers to the capability of resources being available over the network through standard mechanisms, not to scaling. Option C is wrong because measured service relates to monitoring, controlling, and reporting resource usage for billing and metering, not to rapid scaling. Option D is wrong because resource pooling describes the multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to demand, but it does not specifically ensure rapid scaling up and down.

54
MCQeasy

Which characteristic of cloud computing allows a user to automatically provision computing resources without requiring human interaction with the service provider?

A.On-demand self-service
B.Rapid elasticity
C.Broad network access
D.Resource pooling
AnswerA

On-demand self-service lets consumers provision compute, storage and networking capabilities unilaterally through automated interfaces, with no human interaction from the provider. This matches the stem's requirement precisely, distinguishing it from broad network access or rapid elasticity.

Why this answer

On-demand self-service is the essential cloud characteristic that enables a consumer to unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. This is exactly what the question describes: automatic provisioning without human interaction. Rapid elasticity, broad network access, and resource pooling are related but distinct characteristics that do not specifically address the automatic provisioning aspect.

Exam trap

CCSP often tests the distinction between the five essential characteristics of cloud computing, and candidates frequently confuse on-demand self-service with rapid elasticity because both involve automatic scaling; however, the key differentiator is that on-demand self-service is about provisioning without human interaction, while rapid elasticity is about scaling capabilities.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to the ability to scale resources outward and inward commensurate with demand, but it does not inherently include the automatic provisioning without human interaction; elasticity can be achieved manually or automatically, and it focuses on scaling rather than the self-service provisioning mechanism. Option C is wrong because broad network access means capabilities are available over the network through standard mechanisms, but it does not address the automatic provisioning without human interaction; it is about accessibility, not self-service. Option D is wrong because resource pooling refers to the provider's resources being pooled to serve multiple consumers using a multi-tenant model, but it does not describe the user's ability to automatically provision resources without human interaction; it is about the provider's architecture, not the user's self-service capability.

55
MCQmedium

Which cloud characteristic allows a consumer to automatically provision computing resources, such as server time and storage, as needed without requiring human interaction with the service provider?

A.On-demand self-service
B.Rapid elasticity
C.Broad network access
D.Resource pooling
AnswerA

On-demand self-service lets the consumer unilaterally provision capabilities such as server time and storage automatically, with no human interaction required from the provider. That directly matches the stem's requirement for self-provisioning without service provider involvement.

Why this answer

On-demand self-service is the NIST-defined characteristic where a consumer can unilaterally provision computing capabilities, such as server time and storage, automatically without human interaction with the provider. This matches the question's wording exactly.

Exam trap

CCSP often tests the distinction between the five NIST characteristics; candidates confuse on-demand self-service with rapid elasticity because both involve automatic scaling.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to capabilities scaling outward and inward commensurate with demand, not the self-provisioning act itself. Option C is wrong because broad network access means capabilities are available over the network via standard mechanisms. Option D is wrong because resource pooling means provider resources are pooled to serve multiple consumers using a multi-tenant model.

56
Multi-Selectmedium

A company is considering migrating its customer relationship management (CRM) system to a SaaS provider. Which TWO of the following security responsibilities typically remain with the customer in a SaaS deployment?

Select 2 answers
A.Physical security of data centers
B.Operating system patching
C.User access management
D.Application vulnerability management
E.Data classification and access control
AnswersC, E

In SaaS, the provider secures the application and infrastructure, but the customer still governs its own tenants, roles and credentials. User access management stays with the customer because it controls who within the organisation may reach the CRM data, satisfying the stem's split of responsibility.

Why this answer

In a SaaS deployment, the customer retains responsibility for managing its own users and identities, so user access management (C) — provisioning, deprovisioning, role assignment, and enforcing least privilege through SSO/MFA — stays with the customer. Likewise, data classification and access control (E) remain customer duties because the customer owns the data and must define its sensitivity, retention, and who may access it, even though the provider secures the underlying platform. Physical security of data centers (A) is handled by the SaaS provider, which owns and operates the facilities.

Operating system patching (B) is the provider's responsibility since the customer has no access to the underlying OS in a SaaS model. Application vulnerability management (D) also belongs to the provider, as it develops, hosts, and maintains the SaaS application itself.

Exam trap

The trap is assuming the customer still patches the OS or manages application vulnerabilities in SaaS; those shift to the provider, leaving identity and data governance with the customer.

57
MCQhard

A cloud provider's SLA guarantees 99.95% uptime for a service. Over a one-year period (365 days), what is the maximum allowed downtime in minutes to meet this SLA?

A.525.6 minutes
B.262.8 minutes
C.87.6 minutes
D.438 minutes
AnswerB

A 99.95% uptime guarantee permits 0.05% annual downtime. Converting 365 days to 525,600 minutes and multiplying by 0.0005 yields 262.8 minutes, satisfying the stem's one-year calculation constraint. This matches the permitted outage budget exactly, unlike options derived from monthly figures or incorrect percentage conversions.

Why this answer

99.95% uptime over 365 days allows 0.05% downtime. 365 days is 525,600 minutes; 0.05% of 525,600 is 262.8 minutes. Therefore the maximum allowed downtime is 262.8 minutes.

Exam trap

The trap is miscomputing the percentage or using the wrong base (e.g., 365 days vs. 30 days), leading to selecting 525.6 or 87.6 minutes instead of 262.8.

How to eliminate wrong answers

Option A is wrong because 525.6 minutes corresponds to 99.9% uptime (0.1% downtime), not 99.95%. Option C is wrong because 87.6 minutes corresponds to 99.9833% uptime (0.0167% downtime), which is stricter than the stated SLA. Option D is wrong because 438 minutes corresponds to approximately 99.9167% uptime, not 99.95%.

58
MCQeasy

A company wants to migrate its customer relationship management (CRM) system to the cloud and requires that the provider manages the underlying infrastructure, operating system, and middleware, while the company manages only the application and data. Which cloud service model best meets these requirements?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerB

PaaS delivers managed runtime, middleware, and operating system, leaving the customer responsible only for the application and its data. This precisely matches the stem's split of duties: the provider handles infrastructure through middleware, while the company retains the CRM application and data. IaaS would leave OS patching to the company; SaaS would remove application control.

Why this answer

PaaS provides a managed platform where the provider handles the underlying infrastructure, operating system, and middleware (runtime, databases, web servers), while the customer manages only the application and data. This exactly matches the requirement that the company manages only the application and data. Examples include AWS Elastic Beanstalk, Google App Engine, and Azure App Service.

Exam trap

The trap is selecting SaaS because it sounds like the most managed option — but SaaS means the provider manages the application, whereas the question requires the company to manage the application and data, which is PaaS.

How to eliminate wrong answers

Option A is wrong because SaaS delivers a fully managed application where the customer manages only configuration and data — the provider manages the application itself, so the company would not be managing the application as required. Option C is wrong because IaaS provides only virtualized infrastructure (compute, storage, network), leaving the customer responsible for the OS, middleware, and application — far more than the company wants to manage. Option D is wrong because FaaS (serverless functions) abstracts even the application runtime, requiring the customer to deploy only code snippets; it does not fit a CRM system where the company manages the full application.

59
MCQhard

Which cloud design principle is most directly related to ensuring that an organization can migrate workloads from one cloud provider to another without significant re-engineering?

A.Portability
B.Reversibility
C.Multi-tenancy isolation
D.Elasticity
AnswerA

Portability directly addresses the stem's constraint: avoiding significant re-engineering when moving workloads between providers. It relies on provider-neutral abstractions—containers, open APIs, infrastructure-as-code—rather than proprietary services, so workloads can be redeployed elsewhere with minimal modification. Interoperability concerns data exchange between systems, whereas portability concerns relocating the workload itself.

Why this answer

Portability is the cloud design principle specifically concerned with avoiding provider lock-in by designing workloads so they can be moved between cloud providers with minimal re-engineering. It emphasizes use of open standards, containerization, abstraction layers, and portable data formats so that the same workload can run on AWS, Azure, or GCP without significant refactoring. This directly matches the scenario of migrating workloads across providers without significant re-engineering.

Exam trap

The trap here is confusing portability with reversibility — both relate to avoiding lock-in, but portability is about moving workloads between providers, while reversibility is about exiting the cloud entirely or returning data/processing to on-premises.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to exit a cloud relationship and bring data/processing back on-premises or to another environment, focusing on exit strategy and data retrieval rather than cross-provider workload portability. Option C is wrong because multi-tenancy isolation concerns separating tenant data and resources within a shared cloud environment, which is a security/architecture concern, not a migration concern. Option D is wrong because elasticity refers to automatically scaling resources up and down based on demand, which is a scalability characteristic and unrelated to moving workloads between providers.

60
MCQmedium

A media production company needs to process high-resolution video renders that require tightly coupled, low-latency inter-node communication. The company is evaluating cloud deployment models and wants to retain full control over the hardware, hypervisor, and network fabric while still using cloud burst capacity. Which cloud deployment model BEST meets these requirements?

A.Community cloud
B.Public cloud
C.Private cloud
D.Hybrid cloud
AnswerD

Hybrid cloud combines a private cloud that the company controls (hardware, hypervisor, network fabric) with public cloud burst capacity. This matches the requirement to keep tightly coupled, latency-sensitive rendering on controlled infrastructure while elastically extending to public resources during peak demand, preserving both control and scalability.

Why this answer

The scenario requires both exclusive control over the underlying infrastructure and the ability to extend into elastic public capacity on demand. A hybrid cloud is the only model that pairs a controlled private environment with public cloud bursting, satisfying the latency-sensitive rendering requirements while avoiding permanent over-provisioning of owned hardware.

Exam trap

The trap here is assuming that any cloud model offering scalability also offers the infrastructure control needed for tightly coupled, low-latency workloads.

61
MCQmedium

A community cloud is best suited for which scenario?

A.A startup wanting to minimize costs by sharing resources with the general public
B.A single organization needing dedicated infrastructure
C.A company that needs to burst workloads to the public cloud during peak times
D.Several government agencies with similar security and compliance requirements
AnswerD

A community cloud is shared infrastructure provisioned for a specific community of organisations with common concerns. Several government agencies with similar security and compliance requirements fit this model, sharing cost and controls while excluding the general public.

Why this answer

A community cloud is shared infrastructure provisioned for exclusive use by a specific community of consumers from organizations that have shared concerns (e.g., mission, security requirements, policy, compliance). Several government agencies with similar security and compliance requirements is the canonical example, because they can share costs while meeting common regulatory mandates like FedRAMP or CJIS. The defining trait is a bounded community with shared interests, not the general public.

Exam trap

The trap is that 'community cloud' sounds like it serves the general public, so candidates pick the public-cloud answer — the exam expects you to know the community is a bounded group with shared compliance or mission needs.

How to eliminate wrong answers

Option A is wrong because sharing resources with the general public describes a public cloud, not a community cloud — community clouds are restricted to a defined group. Option B is wrong because a single organization needing dedicated infrastructure describes a private cloud, which is exclusive to one entity. Option C is wrong because bursting to the public cloud during peak times describes a hybrid cloud deployment model, which combines private and public resources.

62
MCQmedium

A cloud architect is designing a solution that must automatically scale compute resources based on real-time demand. The application is stateless and can tolerate brief interruptions. Which cloud design principle is most directly addressed by this requirement?

A.Broad network access
B.Measured service
C.Rapid elasticity
D.Resource pooling
AnswerC

Rapid elasticity is the principle of automatically provisioning and releasing resources to match demand, which is exactly what the stem's real-time scaling requirement describes. Statelessness and tolerance of brief interruptions make this horizontal, demand-driven scaling viable.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to scale automatically and dynamically based on demand, including scaling out and in quickly. The requirement for automatic scaling of stateless compute based on real-time demand directly maps to this principle. It ensures capacity matches workload without manual intervention.

Exam trap

The trap is that candidates confuse rapid elasticity with resource pooling or measured service, because all three are cloud characteristics — the exam tests whether you can map a specific requirement (automatic scaling) to the correct NIST characteristic.

How to eliminate wrong answers

Option A is wrong because broad network access refers to services being available over the network via standard mechanisms, not to scaling behavior. Option B is wrong because measured service refers to metering and pay-per-use billing, not automatic scaling. Option D is wrong because resource pooling refers to multi-tenant sharing of physical resources, which enables elasticity but does not itself describe automatic scaling.

63
MCQeasy

Which cloud service model provides the customer with the most control over the underlying infrastructure, including operating systems and applications?

A.IaaS
B.PaaS
C.SaaS
D.FaaS
AnswerA

IaaS delivers compute, storage and networking while the customer manages operating systems, middleware and applications. That leaves the customer controlling more of the stack than PaaS or SaaS permit, satisfying the stem's requirement for the greatest infrastructure control.

Why this answer

IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical host, hypervisor, and networking fabric. This is the highest level of customer control among the four models listed. PaaS, SaaS, and FaaS progressively abstract away more of the stack, reducing customer control.

Exam trap

The trap is assuming 'most control' means 'most secure' or 'most managed' — the exam tests whether you know IaaS sits at the top of the customer-control spectrum, not the provider-responsibility spectrum.

How to eliminate wrong answers

Option B is wrong because PaaS abstracts the OS and runtime, so the customer controls only the application and its configuration, not the underlying infrastructure. Option C is wrong because SaaS delivers a fully managed application where the customer controls only data and user access, not the OS or infrastructure. Option D is wrong because FaaS (serverless) abstracts even the runtime and scaling, leaving the customer responsible only for function code and configuration.

64
MCQeasy

In a hybrid cloud deployment, which of the following is a critical security consideration?

A.Ensuring consistent security policy across environments
B.Using only public cloud for sensitive data
C.Avoiding any use of APIs for integration
D.Eliminating all private cloud resources
AnswerA

Hybrid cloud spans on-premises and cloud environments, so inconsistent policies create gaps attackers can exploit between them. Enforcing a uniform security policy across both satisfies the need for coherent controls, identity, and monitoring regardless of where workloads reside.

Why this answer

Consistent security policy across environments is critical in hybrid cloud because workloads and data span on-premises and cloud boundaries, and inconsistent controls create gaps attackers can exploit. Unified policy ensures identity, encryption, logging, and access controls are applied uniformly. This is a foundational governance requirement for hybrid architectures.

Exam trap

The trap is picking an option that sounds secure but is actually an architectural anti-pattern (e.g., 'use only public cloud' or 'avoid APIs') — the exam wants the governance principle of consistent policy across environments.

How to eliminate wrong answers

Option B is wrong because using only public cloud for sensitive data contradicts hybrid strategy and may violate data residency or compliance requirements; it is not a security consideration but a flawed constraint. Option C is wrong because avoiding APIs for integration is impractical and insecure — APIs are the primary integration mechanism in hybrid cloud, and avoiding them prevents automation and consistent policy enforcement. Option D is wrong because eliminating all private cloud resources defeats the purpose of a hybrid deployment and ignores the security benefits of private environments for sensitive workloads.

65
Multi-Selecthard

An enterprise is evaluating a cloud service provider for a workload that handles regulated data. The security architect must assess whether the provider's cloud architecture supports the organization's data residency and audit obligations. Which TWO of the following are the MOST relevant architectural artifacts to request from the provider? (Choose two.)

Select 2 answers
A.Independent third-party audit reports and certifications such as SOC 2 and ISO/IEC 27001
B.The provider's current stock price and quarterly earnings report
C.A data flow diagram showing where data is stored, processed, and replicated across regions
D.A copy of the provider's internal employee acceptable use policy
E.The provider's marketing brochure describing its global footprint and uptime record
AnswersA, C

Independent audit reports and certifications provide evidence that the provider's controls have been examined against recognized criteria. They support the organization's own audit and compliance obligations by offering verifiable assurance about security, availability, and processing integrity. They also help map provider controls to regulatory requirements during due diligence.

Why this answer

Assessing data residency and audit obligations requires verifiable evidence about where data lives and how controls are validated. A data flow diagram identifies storage, processing, and replication locations, while independent audit reports and certifications demonstrate that controls have been examined against recognized standards. Together they give the architect the factual basis needed for compliance due diligence.

Exam trap

The trap here is accepting vendor-provided assurances or business documents in place of verifiable architectural and audit evidence.

66
MCQhard

An organization is migrating a legacy application to the cloud and wants to minimize vendor lock-in. They plan to use containers orchestrated by Kubernetes. Which design principle is the organization primarily applying?

A.Elasticity
B.Multitenancy isolation
C.Reversibility
D.Portability
AnswerD

Portability is the design principle enabling workloads to move between providers without significant rework. Containers orchestrated by Kubernetes abstract the underlying infrastructure, so the application runs consistently across clouds, directly reducing vendor lock-in as the organisation intends.

Why this answer

Portability is the design principle of avoiding dependence on a specific vendor's proprietary services so workloads can move between environments. Using containers orchestrated by Kubernetes is a classic portability strategy because container images and Kubernetes manifests are largely vendor-neutral. This directly addresses the goal of minimizing vendor lock-in.

Exam trap

The trap is confusing portability with reversibility or elasticity — candidates see 'minimize vendor lock-in' and may pick reversibility, but the container/Kubernetes context signals portability as the primary design principle.

How to eliminate wrong answers

Option A is wrong because elasticity refers to the ability to scale resources up and down automatically based on demand, not to avoiding vendor lock-in. Option B is wrong because multitenancy isolation is about separating tenants' data and workloads in a shared environment, not about portability across providers. Option C is wrong because reversibility is a related but distinct concept — it refers to the ability to revert to a previous state or exit a service, whereas portability is about moving workloads between platforms; the question's emphasis on containers and Kubernetes points to portability as the primary principle.

67
MCQeasy

Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?

A.PaaS
B.SaaS
C.IaaS
D.CaaS
AnswerA

PaaS supplies runtimes, libraries and tools so the consumer deploys custom code without managing servers, operating systems or middleware. That matches the stem exactly: provider-supplied programming languages and tools, with no control over underlying infrastructure.

Why this answer

PaaS (Platform as a Service) provides a managed runtime environment where consumers deploy applications built with provider-supported languages, libraries, and tools, while the provider manages the underlying servers, storage, networking, and OS. The consumer controls only the deployed application and its configuration, not the infrastructure — exactly matching the scenario described.

Exam trap

CCSP often tests the boundary between PaaS and CaaS — candidates see 'deploy and run applications' and pick CaaS, but the question's mention of provider programming languages, libraries, and tools is the classic PaaS definition, not container orchestration.

How to eliminate wrong answers

Option B (SaaS) is wrong because SaaS delivers fully functional applications to end users (e.g., Office 365, Salesforce), not a development platform where consumers deploy their own custom code. Option C (IaaS) is wrong because IaaS provides raw compute, storage, and networking where the consumer manages the OS, middleware, and runtime — the opposite of 'no infrastructure management.' Option D (CaaS) is wrong because Containers as a Service is a subset of PaaS focused on container orchestration (e.g., EKS, AKS, GKE); while related, the question's emphasis on programming languages, libraries, and tools points to the broader PaaS definition.

68
MCQeasy

A startup is developing a new mobile application and wants to minimize infrastructure management while focusing on code development. The team has limited operational resources and prefers a serverless approach. Which cloud service model should they adopt?

A.Platform as a Service (PaaS)
B.Infrastructure as a Service (IaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerD

FaaS is a serverless compute model where the cloud provider manages the infrastructure, scaling, and availability. Developers only write and deploy functions that are triggered by events. This aligns perfectly with the startup's need to minimize infrastructure management and focus on code. It also scales automatically and charges only for actual usage, which is cost-effective for sporadic workloads.

Why this answer

FaaS is the most serverless option, allowing developers to run code in response to events without provisioning or managing servers. It aligns with the startup's goal of minimizing infrastructure management and focusing on code development. The provider handles all scaling, patching, and capacity planning, making it ideal for teams with limited operational resources.

Exam trap

The trap here is confusing PaaS with FaaS, as both abstract infrastructure, but FaaS is more serverless and event-driven, requiring even less operational effort.

69
MCQeasy

An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?

A.Applying hypervisor patches to the multi-tenant virtualization layer
B.Patching the guest operating system on the provider's hosts
C.Managing user identities, access rights, and data classification
D.Maintaining the physical security of the provider's data centers
AnswerC

Even when the provider operates the application stack, the subscriber remains accountable for who may access the service and what data is placed in it. Identity lifecycle management, entitlement review, multi-factor authentication enforcement, and classifying the data being uploaded are classic consumer responsibilities. These controls govern the subscriber's own users and information rather than the provider's infrastructure, so they stay with the consumer.

Why this answer

In SaaS the provider secures everything from the physical facility up through the application, while the consumer retains control over its own identities, access entitlements, and the data it chooses to place in the service. Physical security, hypervisor maintenance, and guest operating system patching all sit beneath the application and never move to the subscriber.

Exam trap

The trap here is assuming that because the provider runs the application, the consumer has no security duties left, when identity and data governance always stay with the subscriber.

70
MCQhard

An organization is evaluating cloud service providers and notices that one provider's SLA offers 99.99% availability for a specific service, while another offers 99.9%. If the service costs $100,000 per month, what is the maximum allowable downtime per month for the 99.99% SLA?

A.8.64 minutes
B.43.2 minutes
C.2.16 minutes
D.4.32 minutes
AnswerD

99.99% availability permits 0.01% downtime. In a 30-day month of 43,200 minutes, that equals 4.32 minutes of maximum allowable downtime, matching the stem's monthly cost basis. The 99.9% figure would instead allow roughly 43.2 minutes.

Why this answer

The 99.99% SLA allows for a maximum of 0.01% downtime per month. Assuming a 30-day month (43,200 minutes), 0.01% of 43,200 minutes is 4.32 minutes. Therefore, the correct answer is 4.32 minutes.

Exam trap

CCSP often tests the ability to convert availability percentages into actual downtime, and candidates frequently misplace a decimal point or confuse 99.9% with 99.99%, leading to errors like choosing 43.2 minutes instead of 4.32 minutes.

How to eliminate wrong answers

Option A is wrong because 8.64 minutes corresponds to 99.98% availability (0.02% downtime), not 99.99%. Option B is wrong because 43.2 minutes corresponds to 99.9% availability (0.1% downtime), which is the other SLA mentioned. Option C is wrong because 2.16 minutes corresponds to 99.995% availability (0.005% downtime), a higher availability tier than 99.99%.

71
MCQeasy

A small business wants to use a cloud-based email and collaboration suite where the provider manages the application, servers, and operating system. The business only needs to configure user accounts and settings. Which cloud service model is being used?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerA

SaaS delivers a complete application managed by the provider, including servers, operating system, and application maintenance. The customer only configures user accounts and settings. This exactly matches the scenario where the business uses a cloud-based email and collaboration suite without managing infrastructure or the application itself.

Why this answer

SaaS is the model where the provider manages the entire application stack, and the customer only handles configuration and user management. The scenario explicitly states the provider manages the application, servers, and operating system, leaving only account and settings configuration to the business. IaaS, PaaS, and FaaS all require more customer responsibility for the application or runtime.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when a fully managed application with only user configuration is SaaS.

72
Multi-Selecteasy

Which TWO of the following are essential characteristics of cloud computing as defined by NIST SP 800-145?

Select 2 answers
A.Measured service
B.Multitenancy
C.Virtualization
D.Auditability
E.Resource pooling
AnswersA, E

Measured service is one of the five essential characteristics in NIST SP 800-145: resource usage is monitored, controlled and reported, providing transparency for both provider and consumer. Metering underpins the pay-per-use billing model that distinguishes cloud from traditional hosting.

Why this answer

NIST SP 800-145 defines five essential characteristics of cloud computing, and 'Measured service' (A) is one of them: cloud systems automatically control and optimize resource use via metering capabilities, providing transparency for both provider and consumer. 'Resource pooling' (E) is also an essential characteristic, where the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with resources dynamically assigned and reassigned according to demand. Multitenancy (B) is a consequence of resource pooling but is not itself listed as a separate essential characteristic in NIST SP 800-145. Virtualization (C) is a common enabling technology for cloud computing but is not one of the five NIST essential characteristics.

Auditability (D) is a desirable governance property but is not included in the NIST definition of essential cloud characteristics.

Exam trap

CCSP often tests the distinction between NIST's five essential characteristics and commonly associated but non-listed concepts like multitenancy and virtualization, which candidates mistakenly select because they are ubiquitous in cloud implementations.

73
MCQeasy

A startup wants to deploy a new web application without purchasing servers or managing operating systems, and it prefers to focus only on writing code while the provider handles runtime, scaling, and patching. Which cloud service model aligns BEST with this goal?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Desktop as a Service (DaaS)
AnswerA

PaaS supplies a managed runtime, middleware, and scaling environment so developers deploy code without provisioning servers or patching operating systems. This matches the startup's objective of writing code while the provider handles runtime, scaling, and patching, offering the right abstraction level between raw infrastructure and a finished application.

Why this answer

PaaS is designed to abstract away servers, operating systems, and runtime management while still allowing custom application deployment. The startup wants to write code and let the provider handle patching and scaling, which is exactly the division of labor PaaS provides, unlike IaaS where infrastructure remains the customer's concern or SaaS where no custom code is deployed.

Exam trap

The trap here is conflating PaaS with IaaS by assuming any cloud model removes server management, when only PaaS removes operating system and runtime administration while preserving custom code deployment.

74
MCQeasy

Which characteristic of cloud computing allows a user to provision resources automatically without requiring human interaction with the service provider?

A.Rapid elasticity
B.Broad network access
C.On-demand self-service
D.Resource pooling
AnswerC

On-demand self-service is the essential characteristic that lets consumers unilaterally provision computing capabilities, such as server time and network storage, automatically as needed, without requiring human interaction with each service provider, directly satisfying the stem's constraint.

Why this answer

On-demand self-service is the cloud characteristic defined by NIST SP 800-145 that allows a consumer to unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. This exactly matches the scenario of automatic provisioning without provider interaction.

Exam trap

The trap is that candidates conflate 'automatic provisioning' with 'rapid elasticity' — both involve automation, but elasticity is about scaling up/down with demand, whereas on-demand self-service is specifically about the consumer provisioning resources without provider interaction.

How to eliminate wrong answers

Option A (Rapid elasticity) is wrong because it describes the ability to scale resources outward and inward commensurate with demand, not the self-service provisioning mechanism itself. Option B (Broad network access) is wrong because it refers to capabilities being available over the network through standard mechanisms and heterogeneous client platforms, not automated provisioning. Option D (Resource pooling) is wrong because it describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, which is about provider-side architecture, not consumer self-service.

75
Multi-Selectmedium

A cloud security architect is designing a multi-tenant SaaS application that must ensure strong isolation between tenants. Which TWO mechanisms are most effective for achieving multitenancy isolation?

Select 2 answers
A.Hypervisor-based virtual machine isolation
B.Network micro-segmentation
C.Encryption at rest for all tenant data
D.Database row-level permissions
E.API rate limiting per tenant
AnswersA, B

Hypervisor-based virtual machine isolation places each tenant's workload in a separate VM, so the hypervisor enforces hardware-level separation of memory, CPU and devices. This strong boundary satisfies the stem's requirement for robust isolation between tenants in a multi-tenant SaaS design.

Why this answer

Hypervisor-based virtual machine isolation (A) is correct because each tenant runs in its own VM with a separate guest OS, so the hypervisor enforces hardware-level separation of CPU, memory, and I/O, preventing one tenant from accessing another tenant's resources even if the guest OS is compromised. Network micro-segmentation (B) is correct because it applies granular, workload-level policies (e.g., security groups, NSGs, or service-mesh rules) that restrict east-west traffic so tenants can only reach their own components, containing lateral movement and enforcing tenant boundaries at the network layer. Encryption at rest (C) is not the most effective isolation mechanism because it protects data confidentiality if storage media is compromised but does not prevent a tenant from accessing another tenant's data through a running application or shared service.

Database row-level permissions (D) provide logical access control within a shared schema but rely on correct query and policy configuration, so they are weaker than infrastructure-enforced isolation and can be bypassed by application or SQL flaws. API rate limiting per tenant (E) addresses fairness, abuse prevention, and availability (e.g., throttling to protect against noisy-neighbor effects) but does not isolate tenants' data or execution environments.

Exam trap

CCSP often tests the difference between confidentiality controls (encryption) and isolation controls (hypervisor, network segmentation), causing candidates to select encryption at rest as an isolation mechanism when it only protects data at rest.

Page 1 of 2 · 117 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cloud Concepts, Architecture, and Design questions.