Courseiva

CCNA Cloud Concepts, Architecture, and Design Questions

42 of 117 questions · Page 2/2 · Cloud Concepts, Architecture, and Design · Answers revealed

76
MCQmedium

In a public cloud IaaS model, which of the following security controls is the cloud customer primarily responsible for implementing?

A.Hypervisor security
B.Network infrastructure security
C.Physical security of data centers
D.Guest OS patch management
AnswerD

In IaaS the provider secures the physical hosts, hypervisor and network fabric, while the customer controls everything above, including the guest operating system. Patching the guest OS therefore falls to the customer, satisfying the stem's question of primary customer responsibility.

Why this answer

The customer is responsible for securing the guest OS and applications.

77
MCQeasy

Which characteristic of cloud computing allows a user to provision computing resources automatically without requiring human interaction with the service provider?

A.Rapid elasticity
B.Broad network access
C.On-demand self-service
D.Measured service
AnswerC

On-demand self-service lets consumers provision capabilities, such as server time and network storage, automatically through a provider's portal or API, with no human interaction on the provider side. This directly satisfies the stem's requirement for automatic provisioning without provider involvement, distinguishing it from broad network access or rapid elasticity.

Why this answer

On-demand self-service is the NIST SP 800-145 characteristic that lets a consumer unilaterally provision computing capabilities, such as server time and network storage, automatically as needed without requiring human interaction with each service provider. This is exactly the ability described in the question. The other characteristics address elasticity, network reachability, and metering, not automated provisioning without provider involvement.

Exam trap

The trap here is confusing on-demand self-service with rapid elasticity, since both involve automatic scaling; the key differentiator is that self-service is about provisioning without provider interaction, while elasticity is about scaling capacity to demand.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to capabilities appearing to be unlimited and scaling out/in quickly to match demand, not to the consumer's ability to self-provision without provider interaction. Option B is wrong because broad network access means services are available over the network through standard mechanisms and heterogeneous client platforms, which is about reachability, not automated provisioning. Option D is wrong because measured service means resource usage is monitored, controlled, and reported for billing and optimization, which is about metering rather than self-service provisioning.

78
MCQmedium

A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?

A.Using a single cloud provider for both environments
B.Ensuring high-speed network connectivity
C.Maintaining consistent security policies across both environments
D.Implementing data encryption at rest only
AnswerC

Hybrid splits workloads across two trust domains, so a single control framework must span both. Consistent policies satisfy the stem's need to govern sensitive on-premises systems and public cloud workloads under one security posture, preventing gaps where data crosses the boundary.

Why this answer

In a hybrid cloud model, the most critical security consideration is maintaining consistent security policies across both on-premises and public cloud environments. This ensures that security controls, access management, data protection, and compliance requirements are uniformly enforced, reducing gaps that attackers could exploit. Inconsistencies can lead to misconfigurations, unauthorized access, and data leakage between environments.

While network connectivity and encryption are important, they are components of a broader policy consistency strategy.

Exam trap

CCSP often tests the misconception that encryption or network speed alone solves hybrid cloud security, but the exam expects recognition that policy consistency and unified governance are the foundation for secure hybrid architectures.

How to eliminate wrong answers

Option A is wrong because using a single cloud provider does not address the hybrid nature; the company already has on-premises workloads, and a single provider may not be feasible or optimal. Option B is wrong because high-speed network connectivity is an availability and performance consideration, not the most critical security consideration; it does not ensure security policy enforcement. Option D is wrong because implementing data encryption at rest only is insufficient; it ignores data in transit, access controls, and policy consistency across environments, and encryption alone does not address all security risks.

79
Multi-Selectmedium

A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)

Select 2 answers
A.An identity and access management framework with least privilege and centralized federation
B.A mandate that all production data remain on dedicated physical hosts owned by the enterprise
C.A data classification and handling policy that maps each data category to approved cloud services
D.A policy prohibiting any use of provider-managed encryption keys for data at rest
E.A requirement that all cloud workloads use the provider's default security configuration
AnswersA, C

In the cloud, identity is the primary security perimeter because there is no physical gate to guard. A federated identity provider with role-based, least-privilege assignments ensures that access to consoles, APIs, and data is centrally granted, reviewed, and revoked. Without this, the enterprise cannot demonstrate who can reach which resources, which is fundamental to governing a multi-tenant environment.

Why this answer

Governance replaces lost physical control with policy and identity. A data classification and handling policy translates business risk into rules about which services, regions, and protections each data category requires, while a federated identity framework with least privilege governs who and what can reach those resources. Default configurations, dedicated-host mandates, and blanket key prohibitions are either too permissive or too rigid to serve as foundational governance.

Exam trap

The trap here is believing that adopting provider defaults or demanding dedicated hardware substitutes for governance, when control in the cloud comes from enterprise-defined policy and identity.

80
Multi-Selecthard

A cloud security team is reviewing a provider's architecture documentation to assess multi-tenancy risks before migrating regulated workloads. The team wants to verify that logical isolation between tenants is enforced at multiple layers. Which TWO provider controls are MOST directly relevant to preventing one tenant from accessing another tenant's data or processes? (Choose two.)

Select 2 answers
A.A disaster recovery plan with a documented recovery time objective
B.A provider-published privacy policy describing data handling practices
C.Tenant-scoped encryption keys with strict key separation and access controls
D.Hypervisor-level virtual machine isolation with separate virtual network segments per tenant
E.A published service level agreement guaranteeing 99.99 percent availability
AnswersC, D

Encrypting each tenant's data with distinct keys, managed under strict access controls, ensures that even if storage media or backups are shared, one tenant cannot decrypt another's data. This cryptographic separation complements logical isolation by protecting data at rest and in transit, directly reducing the impact of any isolation failure in the shared infrastructure.

Why this answer

Preventing cross-tenant access requires controls that enforce boundaries at the compute, network, and data layers. Hypervisor isolation with per-tenant network segmentation separates running workloads and their traffic, while tenant-scoped encryption keys protect data even on shared storage. Governance documents such as SLAs, privacy policies, and disaster recovery plans do not create technical isolation boundaries.

Exam trap

The trap here is selecting contractual or governance artifacts as isolation controls, when only technical mechanisms that enforce separation of execution, networking, or cryptographic keys actually prevent cross-tenant access.

81
Multi-Selectmedium

A cloud architect is designing a multi-tenant SaaS application. Which TWO design principles are critical for ensuring tenant isolation? (Select TWO.)

Select 2 answers
A.Network isolation between tenants
B.Single shared database for all tenants
C.Using the same OS image for all tenants
D.Data isolation (e.g., schema per tenant or encryption)
E.Resource pooling across tenants
AnswersA, D

Segmenting tenant traffic through separate VLANs, subnets or security groups prevents one tenant's workloads from reaching another's, satisfying the isolation constraint at the network layer. Without this, lateral movement across a shared multi-tenant environment becomes possible even when application-level controls are correctly configured.

Why this answer

Network isolation between tenants (A) is critical because it prevents cross-tenant traffic and lateral movement by placing each tenant in separate VPCs, subnets, security groups, or namespaces, ensuring that one tenant's workloads cannot reach another's over the network. Data isolation (D), such as a schema-per-tenant model or per-tenant encryption keys, is equally essential because it guarantees that tenant data is logically or cryptographically separated, preventing unauthorized reads or writes even if application-layer bugs occur. Together, A and D address the two primary isolation dimensions—network and data—required for a secure multi-tenant SaaS design.

A single shared database for all tenants (B) is not a critical isolation principle; without additional controls it actually weakens isolation by co-mingling tenant records. Using the same OS image for all tenants (C) is a standardization and patching benefit, not a tenant-isolation mechanism. Resource pooling across tenants (E) improves cost efficiency and utilization but, by itself, increases the risk of cross-tenant interference rather than ensuring isolation.

Exam trap

CCSP often tests the misconception that resource pooling or shared databases are sufficient for multi-tenancy, but the exam expects recognition that isolation must be enforced at network and data layers to prevent cross-tenant access.

82
MCQhard

An organization needs to migrate a legacy application to the cloud. The application requires full control over the operating system, middleware, and runtime. The team wants to minimize management overhead while retaining OS-level access. Which cloud service model is most appropriate?

A.IaaS
B.SaaS
C.FaaS
D.PaaS
AnswerA

IaaS provides raw compute, storage, and networking while the customer retains full control of the operating system, middleware, and runtime. The provider manages only the underlying infrastructure, satisfying the OS-level access requirement while offloading hardware management, minimising overhead.

Why this answer

IaaS provides virtualized compute, storage, and networking where the customer manages the OS, middleware, and runtime while the provider manages the underlying physical infrastructure. This matches the requirement for full OS-level control with reduced management overhead compared to on-premises. SaaS, PaaS, and FaaS abstract away the OS, so they cannot satisfy the need for OS-level access.

Exam trap

CCSP often tests the shared responsibility boundary, tricking candidates into picking PaaS when the requirement explicitly mentions OS-level control, which only IaaS provides.

How to eliminate wrong answers

Option B is wrong because SaaS delivers a complete application managed by the provider, giving the customer no control over OS, middleware, or runtime. Option C is wrong because FaaS (serverless) abstracts all infrastructure including the runtime, so the customer only supplies function code and has no OS access. Option D is wrong because PaaS provides a managed platform for deploying code but hides the OS and middleware, preventing OS-level control.

83
MCQhard

A company is migrating to a hybrid cloud and needs to ensure consistent security policies across both on-premises and cloud environments. Which of the following is the MOST critical consideration?

A.Implementing single sign-on (SSO) for all users
B.Using dedicated private network connections
C.Choosing the same cloud provider for all public cloud workloads
D.Ensuring that security policies are uniformly applied and enforced across all environments
AnswerD

Uniform enforcement ensures the same controls govern on-premises and cloud resources, closing gaps where workloads move between environments. This directly addresses the stem's requirement for consistent security policies, since inconsistent application creates exploitable seams during and after migration.

Why this answer

The most critical consideration for consistent security policies across hybrid cloud is ensuring that security policies are uniformly applied and enforced across all environments. This ensures that no matter where workloads reside, the same security controls, access rules, and compliance requirements are met, reducing gaps and misconfigurations. While SSO, private connections, and single cloud provider can aid security, they do not guarantee policy consistency; only uniform enforcement does.

Exam trap

CCSP often tests the difference between enabling technologies (like SSO or private links) and the overarching need for consistent policy enforcement, as candidates may focus on specific tools rather than the holistic requirement.

How to eliminate wrong answers

Option A is wrong because implementing SSO improves user authentication convenience and centralizes identity, but it does not ensure that all security policies (e.g., network, data protection) are consistently applied across environments. Option B is wrong because dedicated private network connections enhance security and performance for data transfer, but they do not enforce policy consistency; policies could still diverge. Option C is wrong because choosing the same cloud provider for all public cloud workloads may simplify management but does not address on-premises integration and does not guarantee uniform policy enforcement across hybrid environments.

84
MCQhard

A multinational bank is deploying a hybrid cloud with sensitive workloads on private infrastructure and analytics on a public cloud. The security team must ensure that data classified as confidential never leaves the private environment, while allowing the public cloud to process anonymized datasets. Which cloud deployment model characteristic is MOST relevant to enforcing this boundary?

A.The hybrid model automatically replicates all data to both environments for redundancy.
B.The private cloud eliminates the need for encryption at rest.
C.The hybrid model enables workload placement based on data classification and policy.
D.The public cloud provides stronger physical security than private data centers.
AnswerC

Hybrid cloud allows workloads and data to be placed according to sensitivity and regulatory policy. The bank can keep confidential data on private infrastructure while sending only anonymized datasets to the public cloud. This placement control is the defining characteristic that directly enforces the boundary between environments, making it the most relevant answer.

Why this answer

Hybrid cloud's primary security value in this scenario is the ability to place workloads and data according to classification and policy. The bank can enforce that confidential data stays private while anonymized datasets are processed publicly. Other options either misstate security properties or contradict the requirement, so workload placement based on data classification is the relevant characteristic.

Exam trap

The trap here is confusing hybrid cloud with automatic data replication, when hybrid actually enables policy-driven placement rather than copying everything everywhere.

85
MCQmedium

A security auditor is reviewing a cloud provider's controls to ensure that customer data is appropriately isolated. Which design principle is most directly related to this requirement?

A.Multitenancy isolation
B.Reversibility
C.Portability
D.Elasticity
AnswerA

Multitenancy isolation ensures one tenant's data, workloads, and processes cannot be accessed or affected by another sharing the same infrastructure. This design principle directly satisfies the auditor's requirement that customer data be appropriately segregated within the cloud provider's environment.

Why this answer

Multitenancy isolation is the design principle that ensures customer data and workloads are logically separated in a shared cloud environment. It directly addresses the auditor's requirement by preventing one tenant from accessing another's data through mechanisms like virtual networks, hypervisor separation, and encryption. This principle is fundamental to cloud security and compliance.

Exam trap

CCSP often tests the distinction between cloud characteristics and security principles; candidates may confuse isolation with portability or elasticity, which are about flexibility and scalability, not security separation.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to migrate data and applications back from the cloud to on-premises or another provider, not data isolation. Option C is wrong because portability is about the ease of moving applications and data between cloud environments, which is unrelated to isolation. Option D is wrong because elasticity is the ability to scale resources automatically based on demand, not a security isolation principle.

86
MCQhard

A company plans to deploy a multi-tier application across multiple cloud providers to avoid single points of failure. They need to ensure consistent security policies, including identity federation and network segmentation, across all environments. Which architecture consideration is MOST critical?

A.Using a single cloud provider for all tiers
B.Storing all data in a single provider's data center
C.Using different encryption standards for each provider
D.Implementing a unified security policy management tool
AnswerD

A unified policy management tool enforces identity federation and segmentation rules identically across providers, satisfying the stem's demand for consistent security policies. Without centralised control, each provider's native tooling diverges, creating gaps that undermine the multi-provider redundancy goal.

Why this answer

Implementing a unified security policy management tool is most critical for ensuring consistent security policies, including identity federation and network segmentation, across multiple cloud providers. Such a tool centralizes policy definition, translation, and enforcement, providing a single pane of glass for security management. This addresses the complexity of multi-cloud environments where native tools differ.

Other options either do not address multi-cloud (single provider) or introduce inconsistency (different encryption standards).

Exam trap

CCSP often tests the need for centralized policy management in multi-cloud, as candidates may focus on specific technologies like SSO or encryption but miss the overarching requirement for consistent enforcement across heterogeneous environments.

How to eliminate wrong answers

Option A is wrong because using a single cloud provider for all tiers contradicts the goal of avoiding single points of failure and does not address multi-cloud consistency; it also may not be feasible for all workloads. Option B is wrong because storing all data in a single provider's data center creates a single point of failure and does not support multi-cloud resilience. Option C is wrong because using different encryption standards for each provider leads to inconsistency and potential security gaps, rather than consistent policies.

87
MCQeasy

Which NIST essential characteristic of cloud computing allows the provider to dynamically assign and reassign resources to multiple tenants, often using a multi-tenant model?

A.Resource pooling
B.Rapid elasticity
C.Broad network access
D.Measured service
AnswerA

Resource pooling satisfies the multi-tenant constraint: the provider serves multiple consumers from a shared pool of configurable computing resources, with physical and virtual resources dynamically assigned and reassigned according to demand. Tenants remain isolated yet draw from common infrastructure, which is precisely the mechanism the stem describes.

Why this answer

Resource pooling is the NIST essential characteristic that allows the provider to dynamically assign and reassign physical and virtual resources to multiple tenants using a multi-tenant model. This pooling enables economies of scale and flexibility, as resources are shared and reassigned based on demand. The other characteristics do not specifically describe this dynamic assignment to tenants.

Exam trap

CCSP often tests the NIST definitions, and candidates may confuse resource pooling with rapid elasticity because both involve dynamic resource allocation; however, pooling specifically refers to serving multiple tenants from shared resources.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to the ability to scale resources up and down quickly, not the pooling and reassignment to multiple tenants. Option C is wrong because broad network access means services are available over the network via standard mechanisms, not about resource assignment. Option D is wrong because measured service is about monitoring and metering resource usage for billing, not the dynamic assignment itself.

88
MCQeasy

A company is considering moving its customer relationship management (CRM) system to the cloud. The CRM is accessed through a web browser and the provider handles all maintenance, security, and infrastructure. Which cloud service model is being used?

A.IaaS
B.FaaS
C.SaaS
D.PaaS
AnswerC

SaaS delivers a complete, provider-managed application over the internet, so the vendor handles infrastructure, patching and security while users simply access the CRM through a browser. This satisfies the stem's constraint that the provider manages all maintenance, security and infrastructure, leaving the company only as a consumer of the finished service.

Why this answer

SaaS (Software as a Service) is the correct model because the provider delivers a complete, ready-to-use application (the CRM) over the web while managing all underlying infrastructure, platform, security patching, and maintenance. The customer only interacts with the application through a browser and does not manage servers, middleware, or runtime environments. This matches the classic SaaS definition where the consumer uses the provider's application running on cloud infrastructure.

Exam trap

The trap here is confusing SaaS with PaaS — candidates see 'web browser access' and 'provider handles maintenance' and pick PaaS, forgetting that PaaS still requires the customer to build and manage the application, whereas SaaS delivers the finished application.

How to eliminate wrong answers

Option A is wrong because IaaS provides raw compute, storage, and networking (e.g., AWS EC2) where the customer still manages the OS, middleware, and applications — the CRM provider would not be handling all maintenance. Option B is wrong because FaaS (Function as a Service) is an event-driven serverless compute model for running individual functions, not a full browser-accessed business application. Option D is wrong because PaaS provides a development and deployment platform (e.g., Heroku, App Engine) where the customer still builds and manages the application, whereas here the provider delivers the finished CRM application itself.

89
MCQmedium

A retail company is designing a new cloud architecture for its e-commerce platform. The security team has been asked to define the cloud security architecture. According to the Cloud Security Alliance (CSA) Enterprise Architecture, which of the following is the PRIMARY purpose of the security architecture domain?

A.To ensure that the cloud provider meets all regulatory compliance requirements
B.To define the physical security controls for data centers hosting cloud services
C.To provide a framework for managing security risks and controls across the cloud ecosystem
D.To specify the encryption algorithms required for data at rest and in transit
AnswerC

The security architecture domain in the CSA Enterprise Architecture provides a structured approach to identify, assess, and mitigate security risks across all cloud service and deployment models. It ensures that security controls are integrated into the overall cloud architecture, aligning with business objectives and compliance requirements.

Why this answer

The security architecture domain in the CSA Enterprise Architecture is designed to provide a holistic framework for managing security risks across cloud environments. It integrates security controls and practices into the overall cloud architecture, ensuring that security is aligned with business goals and compliance obligations.

Exam trap

The trap here is confusing the security architecture domain with specific technical controls like encryption or physical security, rather than recognizing its overarching risk management purpose.

90
MCQhard

An organization is evaluating a cloud provider's SLA for a critical application. The provider offers a 99.95% uptime SLA with a 10% service credit for each 30-minute downtime period exceeding the threshold. The organization's business impact analysis requires a maximum downtime of 4.38 hours per year. Does the provider's SLA meet this requirement, and what is the annual allowed downtime based on the SLA?

A.No, because service credits only apply after 30 minutes of downtime, so actual uptime is lower.
B.Yes, because the 10% credit effectively increases the uptime commitment.
C.No, because 99.95% uptime allows 5 hours of downtime per year.
D.Yes, because the SLA guarantees 99.95% uptime, which equals 4.38 hours of downtime per year.
AnswerD

A 99.95% uptime commitment permits 0.05% annual unavailability, which equals 4.38 hours across a 8,760-hour year — precisely the maximum downtime the business impact analysis specifies. The service credit mechanism does not alter this allowance; it only compensates financially once any single 30-minute period exceeds the threshold.

Why this answer

99.95% uptime translates to 0.05% of a year. A standard 365-day year has 8,760 hours, so 8,760 × 0.0005 = 4.38 hours of allowed downtime per year. Since the business impact analysis requires a maximum of 4.38 hours, the SLA exactly meets the requirement.

The 10% service credit is a financial remedy, not an uptime guarantee, so it does not change the calculation.

Exam trap

The trap is confusing service credits with uptime guarantees — candidates assume a 10% credit improves availability, when credits are purely a financial remedy and the uptime percentage is unchanged.

How to eliminate wrong answers

Option A is wrong because the 30-minute credit threshold affects compensation, not the uptime percentage itself — the SLA still commits to 99.95% availability regardless of when credits kick in. Option B is wrong because service credits are refunds, not additional uptime; they do not increase the 99.95% commitment or reduce allowed downtime. Option C is wrong because 99.95% allows 4.38 hours, not 5 hours — 5 hours corresponds to roughly 99.943% uptime, so the math is incorrect.

91
MCQmedium

A software vendor wants to offer its analytics product to several hospitals. Each hospital demands that its data reside on infrastructure dedicated to that hospital, that the hospital retain control over patching windows, and that the vendor's other customers never share the same physical hosts. The hospitals also want to share the cost of the common management tooling the vendor provides. Which cloud deployment model BEST matches these requirements?

A.Hybrid cloud
B.Community cloud
C.Private cloud
D.Public cloud
AnswerB

A community cloud is provisioned for exclusive use by a specific group of consumers that share common concerns such as compliance, security, or mission. The hospitals form exactly such a community, each getting dedicated infrastructure and control over its own patching while sharing the cost of the vendor's common management tooling. This matches the dedicated-tenancy and shared-cost requirements simultaneously.

Why this answer

The hospitals share a common set of concerns, including data residency, tenancy isolation, and patching control, and they want to pool the cost of the vendor's management tooling. That combination of exclusive use by a defined group plus shared economics is the defining characteristic of a community cloud. A public cloud conflicts with dedicated tenancy, a hybrid cloud addresses portability between models, and a private cloud serves one organization rather than a group sharing common requirements.

Exam trap

The trap here is reading dedicated infrastructure and choosing private cloud, overlooking that the consumers are multiple organizations sharing common concerns and costs.

92
MCQmedium

A financial institution is subject to strict regulatory requirements that mandate data residency and physical control over its infrastructure. At the same time, it wants to leverage cloud bursting for peak loads. Which deployment model should the institution adopt?

A.Hybrid cloud
B.Private cloud
C.Community cloud
D.Public cloud
AnswerA

Hybrid cloud keeps regulated data on institution-controlled infrastructure, satisfying data residency and physical control mandates, while public cloud capacity absorbs peak loads through bursting. Neither pure public nor private cloud alone meets both constraints simultaneously.

Why this answer

A hybrid cloud combines a private cloud (or on-premises infrastructure) with public cloud resources, letting the institution keep regulated data and physical control in its private environment while bursting to public cloud for peak loads. This satisfies data residency and physical control requirements while providing elasticity. Private cloud alone cannot burst to public capacity, and public/community clouds do not give the required physical control.

Exam trap

The trap is focusing only on 'cloud bursting' and picking public cloud, or focusing only on 'physical control' and picking private cloud; the correct answer must satisfy both requirements simultaneously, which only hybrid cloud does.

How to eliminate wrong answers

Option B is wrong because a private cloud provides dedicated, controlled infrastructure but lacks the on-demand public capacity needed for cloud bursting during peak loads. Option C is wrong because a community cloud is shared among several organizations with common concerns; it does not give the institution sole physical control over its infrastructure and may not meet strict data residency mandates. Option D is wrong because a public cloud is multi-tenant and provider-controlled, failing the requirement for physical control over infrastructure and often complicating data residency compliance.

93
MCQhard

Which audit report provides the most comprehensive assurance regarding a cloud provider's controls over a period of time, including controls related to security, availability, processing integrity, confidentiality, and privacy?

A.ISO 27001 certification
B.SOC 2 Type I
C.CSA STAR self-assessment
D.SOC 2 Type II
AnswerD

SOC 2 Type II tests control design and operating effectiveness across a defined review period, covering the five trust services criteria named in the stem. Type I only reports design at a single point in time, so it cannot evidence sustained assurance over time.

Why this answer

SOC 2 Type II reports provide assurance over the design AND operating effectiveness of controls across a defined audit period (typically 3–12 months), covering the five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. This period-based testing makes it the most comprehensive assurance option for evaluating a cloud provider's sustained control environment.

Exam trap

CCSP often tests the confusion between SOC 2 Type I (point-in-time design) and Type II (period-based operating effectiveness), and candidates frequently select ISO 27001 thinking certification equals comprehensive control assurance.

How to eliminate wrong answers

Option A is wrong because ISO 27001 certification validates that an information security management system (ISMS) is in place, but it does not provide a detailed audit opinion on the operating effectiveness of specific controls over time. Option B is wrong because SOC 2 Type I only evaluates control design at a single point in time, not operating effectiveness over a period. Option C is wrong because a CSA STAR self-assessment is completed by the cloud provider itself and carries no independent auditor attestation, making it the weakest form of assurance.

94
MCQmedium

In the shared responsibility model for public cloud IaaS, which of the following is typically the responsibility of the cloud customer?

A.Network infrastructure redundancy
B.Managing virtual machine guest OS patches
C.Physical security of data centers
D.Patching the hypervisor
AnswerB

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer controls everything from the guest OS upward. Patching the guest operating system is therefore the customer's task, since the provider has no access to or control over that layer.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical facilities, network backbone, and hypervisor, while the customer is responsible for everything from the guest OS upward — including patching the guest operating system, middleware, and applications. Managing VM guest OS patches is therefore a customer responsibility.

Exam trap

The trap is assuming the provider handles all patching in the cloud; candidates must remember that in IaaS the line is drawn at the hypervisor, so guest OS patching belongs to the customer, while hypervisor and physical security belong to the provider.

How to eliminate wrong answers

Option A is wrong because network infrastructure redundancy (physical routers, switches, backbone) is managed by the cloud provider under IaaS. Option C is wrong because physical security of data centers is always the provider's responsibility in public cloud IaaS. Option D is wrong because patching the hypervisor is the provider's responsibility, since the hypervisor is part of the virtualization layer the provider controls.

95
MCQmedium

A financial services company is required to keep customer data within a specific geographic boundary due to regulatory requirements. The company is evaluating cloud deployment models. Which model would best ensure data sovereignty while still providing scalability?

A.Hybrid cloud with public cloud bursting
B.Public cloud with multi-region deployment
C.Community cloud hosted in the required geography
D.Private cloud on-premises
AnswerC

A community cloud is provisioned for exclusive use by a specific community of organisations, so it can be physically hosted within the required geographic boundary, satisfying the data sovereignty constraint. Shared infrastructure among community members still delivers the scalability the company needs.

Why this answer

A community cloud hosted within the required geography is provisioned for exclusive use by a specific community of organizations that share concerns (here, regulatory compliance), and it can be located in the mandated jurisdiction while still offering elastic, multi-tenant-style scalability. This satisfies data sovereignty because the infrastructure and data reside within the geographic boundary, and it provides scalability through shared community resources rather than a single organization bearing the full cost.

Exam trap

The trap is assuming 'private cloud on-premises' is always the most sovereign answer, when the question also demands scalability — community cloud is the model that balances both regulatory boundary and elastic capacity.

How to eliminate wrong answers

Option A is wrong because hybrid cloud with public cloud bursting pushes workloads and potentially data into a public cloud region that may be outside the required geography, violating data sovereignty. Option B is wrong because public cloud multi-region deployment spreads data across regions that may cross national borders, and the customer typically cannot guarantee all replicas stay within the mandated boundary. Option D is wrong because an on-premises private cloud meets sovereignty but does not inherently provide the elastic scalability the question requires, and it is not a cloud deployment model that scales on demand without significant capital investment.

96
MCQhard

A company is designing a multi-cloud strategy to avoid vendor lock-in and ensure portability. They are considering using containers and an open-source orchestration platform. Which of the following is the BEST choice to achieve workload portability across different cloud providers?

A.Kubernetes
B.Azure Functions
C.AWS Lambda
D.VMware vSphere
AnswerA

Kubernetes is an open-source orchestration platform supported by every major provider, so containerised workloads run identically anywhere. This directly satisfies the stem's portability and anti-lock-in constraint, unlike proprietary orchestrators tied to a single vendor's APIs.

Why this answer

Kubernetes is an open-source container orchestration platform that runs on any cloud or on-premises infrastructure, providing a consistent API and workload abstraction that makes containers portable across providers. Because it is not tied to a single vendor, workloads packaged as Kubernetes manifests or Helm charts can be moved between AWS EKS, Azure AKS, Google GKE, or self-managed clusters with minimal changes, directly addressing vendor lock-in and portability.

Exam trap

The trap is picking a serverless service (Lambda, Azure Functions) as a portability solution, when proprietary FaaS platforms are the opposite of vendor-neutral and increase lock-in.

How to eliminate wrong answers

Option B is wrong because Azure Functions is a proprietary serverless platform tied to Microsoft Azure, which increases lock-in rather than reducing it. Option C is wrong because AWS Lambda is a proprietary AWS serverless service, also creating vendor lock-in. Option D is wrong because VMware vSphere is a virtualization platform, not a container orchestration system, and does not provide the multi-cloud workload portability the company seeks.

97
Multi-Selectmedium

Which THREE of the following are benefits of using a hybrid cloud deployment model?

Select 3 answers
A.Elasticity to burst to public cloud during peak demand
B.Simplified SLA management across environments
C.Ability to keep sensitive workloads on-premises while using public cloud for less sensitive ones
D.Consistent security policies can be applied across both environments
E.Eliminates data sovereignty concerns
AnswersA, C, D

Hybrid cloud lets workloads scale into public cloud capacity on demand, so peak loads are absorbed without permanently provisioning on-premises hardware. This elasticity directly delivers the burst capability the stem asks about as a hybrid benefit.

Why this answer

Option A is correct because a hybrid cloud lets workloads that exceed on-premises capacity burst into the public cloud on demand, providing elasticity during peak periods without permanently over-provisioning private infrastructure. Option C is correct because the hybrid model explicitly supports workload placement decisions, allowing sensitive or regulated data to remain on-premises while less sensitive workloads run in the public cloud. Option D is correct because hybrid cloud management tooling and unified control planes (e.g., Azure Arc, AWS Outposts, or VMware vSphere/vCloud integrations) allow consistent security policies, identity controls, and compliance configurations to be applied across both environments.

Option B is not correct because SLAs typically differ between on-premises infrastructure and public cloud providers, and managing them across a hybrid estate is generally more complex, not simplified. Option E is not correct because data sovereignty concerns are not eliminated by hybrid cloud; they must still be addressed through careful workload placement, data residency controls, and jurisdictional compliance, and hybrid deployments can even complicate them.

Exam trap

CCSP often tests the misconception that hybrid cloud simplifies governance and SLAs, when in fact it multiplies the number of trust boundaries and contracts that must be managed.

98
Multi-Selecthard

An organization is migrating a legacy application to the cloud and requires reversibility. Which THREE of the following should be considered to ensure the application can be migrated away from the cloud provider in the future?

Select 3 answers
A.Using containerization with Kubernetes for workload portability
B.Designing the application to use open standards (e.g., OAuth, REST)
C.Using proprietary APIs for storage and compute
D.Implementing auto-scaling policies
E.Ensuring data can be exported in standard formats (e.g., CSV, JSON)
AnswersA, B, E

Containers package the application and its dependencies into a portable image, so Kubernetes can orchestrate that same workload on another provider's cluster. This avoids proprietary runtime lock-in, directly satisfying the reversibility requirement that the application can be migrated away later.

Why this answer

Option A is correct because containerizing workloads with Kubernetes abstracts the application from the underlying cloud infrastructure, so the same container images and manifests can be redeployed on another provider or on-premises cluster, directly supporting reversibility. Option B is correct because designing with open standards such as OAuth for authentication and REST for service interfaces avoids dependence on a single vendor's proprietary protocols, making it feasible to re-host or re-integrate the application elsewhere. Option E is correct because ensuring data can be exported in standard formats like CSV or JSON prevents data lock-in, allowing the organization to move its data to another platform without loss or costly transformation.

Option C is incorrect because proprietary storage and compute APIs increase vendor lock-in and make migration away from the provider harder, which is the opposite of the goal. Option D is incorrect because auto-scaling policies address elasticity and performance, not portability or the ability to exit the cloud provider.

Exam trap

The trap is that auto-scaling sounds like good cloud architecture, so candidates select it as a 'best practice' without checking whether it actually supports the stated goal (reversibility). Always map each option back to the specific requirement.

99
MCQmedium

A healthcare organization is migrating patient records to a public cloud provider. Which of the following is the most critical consideration regarding shared responsibility when using IaaS?

A.The cloud provider is responsible for all security controls because they own the infrastructure.
B.The customer has no responsibility for network security because the provider manages the hypervisor.
C.The cloud provider automatically encrypts all data at rest and in transit by default.
D.The customer is responsible for securing the operating system, applications, and data they deploy on the IaaS platform.
AnswerD

Under the IaaS shared responsibility model the provider secures the physical hosts, hypervisor and facility, while the customer secures everything above: guest operating systems, middleware, applications and patient data. For healthcare records, that customer-side obligation is the most critical consideration.

Why this answer

In IaaS, the provider secures the physical hosts, hypervisor, and network fabric, but the customer retains responsibility for the guest OS, middleware, applications, and data — including patching, hardening, and encryption choices. For a healthcare workload, that means the customer must secure the OS and application layer even though the provider owns the hardware.

Exam trap

CCSP often tests the misconception that the provider handles 'most' security in IaaS, when in fact the customer carries the majority of operational security responsibility for the guest stack.

How to eliminate wrong answers

Option A is wrong because the provider never assumes all security controls in IaaS — that would describe a fully managed SaaS model, not IaaS. Option B is wrong because while the provider manages the hypervisor, the customer is still responsible for guest-level network security such as security groups, host firewalls, and OS-level controls. Option C is wrong because automatic encryption at rest and in transit is not a default guarantee across all IaaS services; encryption is often optional and must be configured by the customer.

100
MCQmedium

A company wants to migrate a legacy application to the cloud with minimal re-architecture. They need control over the operating system and middleware but do not want to manage physical hardware. Which service model is most suitable?

A.FaaS
B.SaaS
C.IaaS
D.PaaS
AnswerC

IaaS delivers virtualised compute, storage and networking while the customer retains control of the operating system and middleware, avoiding physical hardware management. That preserves the legacy application's stack with minimal re-architecture, matching the stem's requirement for OS-level control without hardware ownership.

Why this answer

IaaS provides virtualized compute, storage, and networking where the customer controls the OS and middleware but does not manage physical hardware, matching the requirement for minimal re-architecture with OS-level control. It is the lowest-level cloud service model that still abstracts hardware.

Exam trap

CCSP often tests the boundary between IaaS and PaaS — candidates pick PaaS when the question explicitly requires OS and middleware control, which only IaaS provides.

How to eliminate wrong answers

Option A is wrong because FaaS (serverless) abstracts the OS and runtime entirely, requiring re-architecture into event-driven functions. Option B is wrong because SaaS delivers a finished application with no OS or middleware control. Option D is wrong because PaaS manages the OS and middleware for you, removing the control the company explicitly wants.

101
MCQeasy

Which NIST SP 800-145 cloud service model provides the consumer with the ability to deploy applications onto a cloud infrastructure where the consumer does not manage the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment?

A.Platform as a Service (PaaS)
B.Function as a Service (FaaS)
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerA

Platform as a Service (PaaS) satisfies the stem's constraint: the consumer deploys applications onto provider-managed infrastructure without controlling network, servers, operating systems or storage, yet retains control over deployed applications and possibly application-hosting environment configuration. This matches NIST SP 800-145's PaaS definition precisely, distinguishing it from IaaS, where the consumer manages the operating system.

Why this answer

NIST SP 800-145 defines PaaS as the model where the consumer deploys applications onto cloud infrastructure but does not manage the underlying network, servers, operating systems, or storage. The consumer controls the deployed applications and possibly application-hosting environment configurations — exactly matching the question's description. This is the canonical PaaS definition.

Exam trap

CCSP often tests the precise NIST 800-145 wording — candidates confuse PaaS with IaaS because both allow application deployment, but IaaS requires the consumer to manage the OS and storage, which the question explicitly excludes.

How to eliminate wrong answers

Option B is wrong because FaaS (serverless functions) is a subset of PaaS where the consumer only deploys function code and does not manage any hosting environment configuration — NIST 800-145 does not define FaaS as a separate model. Option C is wrong because SaaS provides the consumer with access to a provider's applications, not the ability to deploy their own applications onto the infrastructure. Option D is wrong because IaaS gives the consumer control over operating systems, storage, and deployed applications — the question explicitly states the consumer does NOT manage the OS or storage.

102
MCQmedium

A cloud architect is mapping security responsibilities for a SaaS customer relationship management deployment. The provider manages the application, runtime, middleware, operating system, and physical infrastructure. Which security task remains the responsibility of the customer organization?

A.Maintaining the physical security of the data center hosting the application
B.Managing user identities, access entitlements, and authentication configuration
C.Patching the operating system and runtime hosting the application
D.Applying firmware updates to the hypervisor and host servers
AnswerB

Even in SaaS, the customer controls who within its organization can access the application, what roles and entitlements they hold, and how authentication integrates with its identity provider. Managing accounts, enforcing least privilege, and revoking access for departing staff remain customer duties because the provider cannot know the organization's business roles or personnel changes.

Why this answer

In every cloud service model, the customer retains responsibility for its own data governance and access management. With SaaS, the provider covers the stack from physical facilities through the application, but identity lifecycle, entitlement decisions, and authentication configuration require knowledge of the customer's personnel and business roles, so those tasks cannot be delegated to the provider.

Exam trap

The trap here is assuming that SaaS means the provider secures everything, when the customer always retains responsibility for identity, access, and its own data handling.

103
MCQmedium

A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?

A.Broad network access
B.Hypervisor-based virtualization and network segmentation
C.Resource pooling
D.Measured service
AnswerB

The hypervisor enforces memory and CPU isolation between virtual machines on the same host, while virtual network segmentation controls traffic between tenants. Together they directly prevent one customer's VM from reading another's memory or reaching its network segments, which is exactly the isolation the security team requires in a multi-tenant public cloud.

Why this answer

Multi-tenant isolation on shared hardware is achieved through the hypervisor, which partitions memory and CPU, and through network segmentation, which restricts traffic flows between tenants. These architectural controls directly satisfy the requirement that different customers' virtual machines cannot access each other's memory or network traffic even when co-located.

Exam trap

The trap here is confusing essential cloud characteristics such as resource pooling or measured service with the security controls that actually enforce tenant isolation.

104
MCQhard

In a public cloud IaaS environment, which of the following is the customer responsible for securing, according to the shared responsibility model?

A.Operating system and applications
B.Virtualization hypervisor
C.Network infrastructure
D.Physical security of data centers
AnswerA

In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains responsibility for everything above it: guest operating system patching, middleware, applications and data. That division satisfies the stem's IaaS shared responsibility question.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical facilities, hardware, hypervisor, and network fabric, while the customer is responsible for everything from the guest operating system upward, including patching, applications, and data. Therefore the customer must secure the operating system and applications they deploy on IaaS instances.

Exam trap

The trap is over-attributing security to the cloud provider; candidates often think the provider secures the OS because it secures the hypervisor, but in IaaS the guest OS is squarely the customer's responsibility.

How to eliminate wrong answers

Option B is wrong because the virtualization hypervisor is part of the provider's managed infrastructure in IaaS; the customer does not control or patch it. Option C is wrong because the underlying network infrastructure (routers, switches, physical links) is owned and secured by the cloud provider. Option D is wrong because physical security of data centers is always the provider's responsibility under every cloud service model.

105
MCQeasy

Which cloud characteristic allows a user to automatically provision computing resources without requiring human interaction with the service provider?

A.Broad network access
B.Rapid elasticity
C.Resource pooling
D.On-demand self-service
AnswerD

On-demand self-service lets the consumer unilaterally provision computing capabilities, such as server time and storage, automatically as needed without human interaction with each provider. This directly matches the stem's requirement for provisioning without human interaction.

Why this answer

On-demand self-service is the NIST-defined cloud characteristic that lets consumers unilaterally provision computing capabilities, such as server time and storage, automatically without requiring human interaction with the service provider. This is exactly what the question describes.

Exam trap

The trap is confusing rapid elasticity with on-demand self-service; both involve automation, but elasticity is about scaling with demand, while self-service is about provisioning without provider interaction.

How to eliminate wrong answers

Option A is wrong because broad network access means services are available over the network via standard mechanisms, not that provisioning is automated. Option B is wrong because rapid elasticity refers to scaling capabilities outward and inward commensurate with demand, not the self-provisioning act itself. Option C is wrong because resource pooling describes the provider's multi-tenant model where resources are dynamically assigned, not the customer's ability to self-provision.

106
Multi-Selectmedium

A cloud security architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms should be implemented to prevent data leakage between tenants?

Select 2 answers
A.API rate limiting
B.Network isolation using virtual networks
C.Storage isolation through separate databases or schemas
D.Data encryption at rest
E.Identity federation
AnswersB, C

Virtual networks segment tenant traffic so one tenant's workloads cannot reach another's at the network layer, blocking lateral movement and cross-tenant access. This satisfies the stem's requirement for isolation mechanisms preventing data leakage between tenants in the multi-tenant SaaS application.

Why this answer

Network isolation using virtual networks (B) is correct because placing each tenant's workloads in separate VNets/subnets (or separate VPCs) with security groups/NSGs and peering rules prevents cross-tenant network traffic and lateral movement, which is a primary vector for data leakage in multi-tenant SaaS. Storage isolation through separate databases or schemas (C) is correct because logically or physically partitioning tenant data (dedicated database per tenant, or schema-per-tenant with strict access controls) enforces a hard data boundary so one tenant's queries cannot read another tenant's records. API rate limiting (A) only protects availability and throttles abuse; it does not create a data boundary.

Data encryption at rest (D) protects data confidentiality if the storage medium is compromised but does not prevent one tenant from accessing another tenant's data through the application. Identity federation (E) addresses authentication and SSO, not tenant data separation.

Exam trap

The trap is selecting encryption at rest as an isolation mechanism; candidates assume encryption prevents data leakage, but it only protects data at the storage layer and does not stop an application from accessing another tenant's records.

107
MCQmedium

An organization is looking for a cloud deployment model that is provisioned for exclusive use by a single organization, but may be owned, managed, and operated by the organization, a third party, or some combination. Which deployment model is this?

A.Hybrid cloud
B.Private cloud
C.Community cloud
D.Public cloud
AnswerB

A private cloud is provisioned for exclusive use by a single organisation, and may be owned, managed, and operated by that organisation, a third party, or a combination, whether on or off premises. This exactly matches the stem's exclusivity and ownership wording.

Why this answer

Private cloud is defined as provisioned for exclusive use by a single organization. It can be on-premises or hosted, and managed by the organization or a third party.

108
MCQeasy

Which cloud characteristic refers to the ability to automatically scale resources up or down based on demand?

A.Resource pooling
B.Rapid elasticity
C.Broad network access
D.Measured service
AnswerB

Rapid elasticity describes resources scaling automatically up or down to match demand, appearing unlimited to the consumer. This directly satisfies the stem's automatic scaling characteristic, distinguishing it from measured service, on-demand self-service and broad network access, which address provisioning, metering and connectivity instead.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to be automatically scaled up or down based on demand. It enables cloud consumers to quickly provision and release resources to match workload fluctuations, often in an automated manner. This is a core tenet of cloud computing as defined by NIST.

Exam trap

The trap is that candidates might confuse rapid elasticity with other characteristics like resource pooling or measured service, especially since all are fundamental to cloud computing.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the sharing of physical resources among multiple tenants, not automatic scaling. Option C is wrong because broad network access means services are available over the network via standard mechanisms, not scaling. Option D is wrong because measured service refers to monitoring and metering resource usage for billing, not scaling.

109
MCQeasy

A startup is deploying a new web application and wants to avoid managing servers, operating systems, or runtime updates. The developers only want to upload code and have the provider handle scaling, patching, and availability. They do not need control over the underlying infrastructure. Which cloud service model is MOST appropriate?

A.DaaS
B.IaaS
C.SaaS
D.PaaS
AnswerD

PaaS lets developers deploy code while the provider manages the underlying servers, operating systems, runtime, scaling, and patching. This matches the startup's requirement to avoid infrastructure management and focus only on application code, making it the most appropriate service model for the described workload.

Why this answer

PaaS abstracts the infrastructure and runtime so developers can focus on code while the provider handles patching, scaling, and availability. Because the startup does not want to manage servers, operating systems, or runtime updates, PaaS aligns directly with its operational and development needs.

Exam trap

The trap here is confusing PaaS with SaaS, since both reduce management burden, but only PaaS lets the organization deploy its own custom application code.

110
MCQmedium

A financial services company is migrating its legacy on-premises application to a public cloud IaaS environment. The application currently uses a shared file system that requires strong consistency and low-latency access for transaction processing. The cloud architect must choose a storage solution that meets these performance requirements. Which cloud storage type is MOST appropriate?

A.Object storage
B.Block storage
C.File storage
D.Archive storage
AnswerC

File storage, often provided as a managed Network File System (NFS) service in the cloud, supports shared access from multiple instances and can provide strong consistency and low latency when provisioned with appropriate performance tiers. It is designed for file-based workloads that require concurrent access, making it suitable for a shared file system used by transaction processing applications.

Why this answer

The application requires a shared file system with strong consistency and low latency. Cloud file storage services, such as Amazon EFS or Azure Files, provide shared NFS or SMB access with configurable performance and strong consistency. Block storage is not inherently shared, object storage is not low-latency or strongly consistent, and archive storage is for cold data.

Therefore, file storage is the most appropriate choice.

Exam trap

The trap here is assuming that block storage is always the best for performance, but block storage is not designed for shared access. File storage is the correct choice when multiple instances need concurrent access to the same file system with strong consistency.

111
MCQmedium

Which of the following is a key consideration when evaluating a cloud service provider's ability to meet compliance requirements for data sovereignty?

A.The provider's support tier
B.The provider's data center locations and geographic restrictions
C.The provider's penetration testing policy
D.The provider's SOC 2 Type II report
AnswerB

Data sovereignty depends on where data physically resides and which jurisdictions govern it. A provider's data centre locations and geographic restrictions determine whether residency obligations can actually be met, making this the decisive compliance consideration.

Why this answer

Data sovereignty requires that data remains subject to the laws of the country where it is stored or processed. Therefore, the provider's data center locations and any geographic restrictions on where data can be stored, processed, or replicated are the primary considerations. This directly determines which legal jurisdictions can claim authority over the data.

Exam trap

CCSP often tests the confusion between data residency (physical location) and data sovereignty (legal jurisdiction), so candidates pick SOC 2 or support tier thinking it covers compliance, when the question specifically asks about geographic restrictions.

How to eliminate wrong answers

Option A is wrong because support tier affects service responsiveness, not legal jurisdiction over data. Option C is wrong because penetration testing policy addresses security assurance, not where data resides or which laws apply. Option D is wrong because a SOC 2 Type II report attests to security controls over time but does not address geographic data residency or sovereignty requirements.

112
MCQmedium

A cloud service provider (CSP) offers a shared infrastructure where multiple customers' virtual machines run on the same physical host but are isolated by the hypervisor. Which cloud deployment model does this represent?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Community cloud
AnswerC

Public cloud matches because the CSP owns the shared infrastructure and serves multiple tenants from one pooled environment. Hypervisor-level isolation between customers' virtual machines on the same physical host is the defining multi-tenancy mechanism of the public deployment model, satisfying the stem's shared-host, provider-operated constraint.

Why this answer

The scenario describes a public cloud deployment model, where a CSP owns and operates the infrastructure and offers services to multiple customers (tenants) over the internet. The key characteristic is multi-tenancy: multiple customers' virtual machines share the same physical host but are logically isolated by the hypervisor. This is the defining trait of a public cloud, as opposed to private, hybrid, or community clouds, which have different ownership and access boundaries.

Exam trap

CCSP often tests the misconception that any shared infrastructure implies a community cloud, but the key differentiator is whether the tenants are a specific group with common interests (community) or the general public (public).

How to eliminate wrong answers

Option A is wrong because a hybrid cloud combines two or more distinct deployment models (e.g., public and private) with technology enabling data and application portability; the scenario describes a single shared infrastructure, not a combination. Option B is wrong because a private cloud is provisioned for exclusive use by a single organization, not multiple customers on shared hardware. Option D is wrong because a community cloud is shared by several organizations with common concerns (e.g., same compliance requirements), but the scenario explicitly states 'multiple customers' without any shared community purpose, and the CSP offers it to the general public.

113
Multi-Selecthard

An organization is migrating a legacy application to the cloud and wants to maximize elasticity. Which THREE characteristics should the application support to benefit from cloud elasticity?

Select 3 answers
A.Distributed architecture
B.Monolithic architecture
C.Horizontal scaling support
D.Stateless design
E.Vertical scaling capability
AnswersA, C, D

A distributed architecture spreads workload across multiple independent components, so additional instances can be added or removed horizontally as demand changes. This stateless, loosely coupled design lets the application scale out and in automatically, which is the prerequisite for realising cloud elasticity.

Why this answer

Option A (Distributed architecture) is correct because spreading workloads across multiple independent components or nodes lets the cloud platform add or remove capacity in parallel, which is essential for elastic scaling. Option C (Horizontal scaling support) is correct because elasticity is achieved primarily by adding or removing instances (scale out/in), so the application must be designed to run across multiple identical instances. Option D (Stateless design) is correct because stateless components do not hold session or local state, allowing any instance to handle any request and enabling instances to be created or destroyed freely during elastic scaling.

Option B (Monolithic architecture) is not correct because a single tightly coupled deployment unit cannot be scaled or updated granularly, limiting elasticity. Option E (Vertical scaling capability) is not correct because vertical scaling means resizing a single server (scale up/down), which is constrained by hardware limits and does not provide the rapid, automated elasticity that horizontal scaling delivers.

Exam trap

CCSP often tests the misconception that vertical scaling (scaling up) is a valid cloud elasticity strategy, but elasticity primarily relies on horizontal scaling and statelessness to achieve dynamic, automated resource adjustments.

114
MCQmedium

A financial institution requires a cloud environment that is shared by multiple organizations with common regulatory compliance needs, such as PCI DSS. Which deployment model is most appropriate?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerC

A community cloud is shared by several organisations with common concerns such as PCI DSS compliance, letting the financial institution share infrastructure and cost while meeting its regulatory needs. This matches the stem's requirement for shared infrastructure among organisations with common compliance obligations.

Why this answer

A community cloud is shared by multiple organizations that have common regulatory or compliance requirements, such as PCI DSS, making it the ideal model for a financial institution needing a compliant shared environment. It provides the cost and scalability benefits of multi-tenancy while meeting sector-specific controls. This matches the definition of community cloud in NIST SP 800-145.

Exam trap

CCSP often tests the distinction between community and public/private clouds by emphasizing 'shared by multiple organizations with common compliance needs,' trapping candidates who default to public cloud for cost or private cloud for security.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated to a single organization, which would not satisfy the requirement for a shared environment across multiple organizations with common compliance needs. Option B is wrong because a public cloud is open to the general public and does not inherently provide the common regulatory governance that a community cloud offers. Option D is wrong because a hybrid cloud combines private and public components for a single organization's workloads; it does not describe a multi-organization shared model with common compliance requirements.

115
MCQeasy

A startup wants to deploy a customer relationship management (CRM) application without managing any servers, operating systems, or middleware. The vendor hosts the application, and the startup's administrators only create user accounts and configure settings through a web interface. Which cloud service category is being used?

A.Software as a Service (SaaS)
B.Infrastructure as a Service (IaaS)
C.Function as a Service (FaaS)
D.Platform as a Service (PaaS)
AnswerA

SaaS delivers a complete, provider-managed application accessed over the network, with the customer responsible only for user administration and configuration. The startup's administrators create accounts and adjust settings through a web interface, exactly matching the SaaS consumption model where no server, OS, or middleware management is performed.

Why this answer

The clue is that the provider hosts the entire application and the customer only manages users and configuration. That is the SaaS model, where the provider owns the application, runtime, middleware, operating system, and infrastructure. IaaS and PaaS leave more layers under customer control, and FaaS is a developer-oriented serverless compute service rather than a finished business application.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when PaaS still requires the customer to deploy and manage its own application code.

116
MCQhard

An organization wants to ensure that if they decide to migrate away from their current cloud provider, they can retrieve all data in a usable format and delete it from the provider's systems. Which principle does this best describe?

A.Interoperability
B.Portability
C.Elasticity
D.Reversibility
AnswerD

Reversibility covers both data portability and secure deletion on exit, matching the requirement to retrieve data in a usable format and remove it from provider systems. It is the cloud-specific counterpart to avoiding vendor lock-in, ensuring the organisation can terminate the relationship without losing access to its own information.

Why this answer

Reversibility is the principle that ensures an organization can fully exit a cloud provider relationship — retrieving all data in a usable format and confirming its deletion from the provider's systems. It directly addresses the exit/termination scenario described, covering both data extraction and verified destruction. This is a core cloud governance concept tied to avoiding vendor lock-in and satisfying data lifecycle obligations.

Exam trap

The trap here is confusing portability (moving workloads) with reversibility (exiting and reclaiming/deleting data) — CCSP often tests this distinction because both relate to avoiding lock-in but address different lifecycle stages.

How to eliminate wrong answers

Option A is wrong because interoperability refers to the ability of different systems or services to exchange and use information, not the ability to exit a provider and reclaim data. Option B is wrong because portability focuses on moving workloads or applications between environments without major rework, but does not inherently include the deletion/verification of data from the original provider. Option C is wrong because elasticity describes the ability to automatically scale resources up or down based on demand, which is unrelated to data retrieval and deletion on exit.

117
MCQmedium

An organization is using a public cloud IaaS and wants to ensure they understand which security responsibilities fall on them. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

A.Hypervisor security
B.Physical security of data centers
C.Security of the guest operating system
D.Network infrastructure hardening
AnswerC

In IaaS, the provider secures the physical hosts, network fabric and hypervisor, while the customer retains control of everything above virtualisation. Patching, hardening and monitoring the guest operating system therefore fall to the organisation, satisfying the stem's requirement to identify customer-side duties.

Why this answer

In an IaaS deployment, the cloud provider secures the physical facility, hardware, and hypervisor, while the customer retains responsibility for everything from the guest OS upward — including OS patching, hardening, host firewalls, and the applications and data running on top. Option C correctly identifies the guest operating system as a customer responsibility. This is the classic 'security OF the cloud vs. security IN the cloud' split defined by the shared responsibility model.

Exam trap

CCSP often tests the boundary of the shared responsibility model — candidates incorrectly assume the provider handles OS or network security in IaaS, when in fact the customer owns everything above the hypervisor.

How to eliminate wrong answers

Option A is wrong because hypervisor security is the cloud provider's responsibility in IaaS — the customer has no access to the hypervisor layer. Option B is wrong because physical security of data centers always belongs to the cloud provider, regardless of service model (IaaS, PaaS, or SaaS). Option D is wrong because the underlying network infrastructure (routers, switches, backbone) is provider-managed in IaaS; the customer only controls virtual network constructs like security groups and NACLs.

← PreviousPage 2 of 2 · 117 questions total

Ready to test yourself?

Try a timed practice session using only Cloud Concepts, Architecture, and Design questions.