Courseiva

CCSP · topic practice

Cloud Concepts, Architecture, and Design practice questions

This domain covers cloud reference architecture, deployment and service models, security design principles, and shared responsibility. It is tested through scenario questions on hybrid/multi-cloud, portability, provider assurance reports like SOC 2 Type II, and SLA availability and financial impact calculations.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cloud Concepts, Architecture, and Design

What the exam tests

What to know about Cloud Concepts, Architecture, and Design

Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.

Shared responsibility across IaaS, PaaS, and SaaS and cloud deployment models

Cloud reference architecture components: BCDR, virtualization, and network security

Provider assurance artifacts such as SOC 2 Type II and ISO/IEC 27001

SLA availability math, downtime, and vendor lock-in mitigation strategies

Watch out for

Common Cloud Concepts, Architecture, and Design exam traps

  • ▸Assuming the provider secures everything; shared responsibility varies by service model and leaves customer duties.
  • ▸Confusing SOC 2 Type II (operating effectiveness over time) with Type I (design at a point in time).
  • ▸Treating 99.99% and 99.9% as similar; small percentage differences create large downtime and financial exposure.

Practice set

Cloud Concepts, Architecture, and Design questions

20 questions · select your answer, then reveal the explanation

A cloud provider offers a service with an SLA of 99.9% availability. Which TWO of the following are likely consequences if the provider fails to meet this SLA?

A cloud provider guarantees 99.99% availability for a service. What is the maximum allowed downtime per year (rounded to nearest minute)?

An organization is adopting a hybrid cloud strategy and needs to ensure secure connectivity between on-premises and cloud environments. Which TWO approaches are most appropriate for this purpose?

A company is evaluating cloud providers for a global application. They need to ensure high availability and low latency. Which THREE factors are most important to consider during provider evaluation? (Select THREE.)

An organization is evaluating cloud service providers and wants to ensure that the provider can demonstrate independent verification of its security controls. Which THREE of the following are recognized cloud security audit reports or certifications?

A cloud architect is designing a multi-tenant SaaS application. Which THREE of the following are essential isolation mechanisms that must be implemented to ensure tenant separation?

Which THREE of the following are valid methods for achieving multitenancy isolation in a public cloud IaaS environment?

A multinational corporation is adopting a hybrid cloud model. The security manager is concerned about data sovereignty and wants to ensure that data stored in the public cloud remains within specific legal jurisdictions. Which of the following cloud deployment models BEST addresses this requirement while still allowing integration with on-premises systems?

A startup is choosing a cloud deployment model for a new application that must meet strict data residency requirements in a single country and be accessible only to employees of that startup. The startup has limited capital and wants to avoid building a data center. Which deployment model is MOST appropriate?

A media company has a streaming platform that experiences unpredictable spikes in viewership during live events. The company wants to ensure the platform remains available during these spikes without over-provisioning resources during normal periods. Which cloud computing service model BEST meets this requirement?

A cloud architect is evaluating a deployment model for a national retail chain. The company wants the cost and scalability benefits of a public cloud but must ensure that its point-of-sale transaction data is processed only by systems dedicated to the retail chain and not shared with any other tenant at the compute layer. Which cloud deployment model BEST satisfies these requirements while retaining public cloud elasticity?

A media company needs to process and store raw video footage during live sporting events, then quickly release the compute capacity once each event ends. The workloads are highly variable and short-lived, often lasting only a few hours. Which cloud service model BEST fits this requirement?

A cloud architect is comparing IaaS, PaaS, and SaaS for a new customer-facing application. The security team wants to minimize the portion of the stack the organization must patch and secure, but the development team insists on controlling the runtime, libraries, and application code. The application also requires a relational database that the organization wants to manage itself. Which cloud service model BEST balances these requirements?

A media production company stores 800 TB of archived video masters that must remain immediately retrievable for seven years. The security architect is comparing storage deployment models and wants to minimize recurring cost while preserving rapid access. Which cloud storage deployment model is MOST appropriate?

A retail enterprise is choosing a cloud deployment model for a new analytics platform that must process regulated payment data. Legal counsel requires that the underlying infrastructure never be shared with unrelated organizations, while the platform must still be able to burst capacity during seasonal peaks. The enterprise already owns two data centers and wants to keep its existing hardware investment productive. Which deployment model BEST satisfies these constraints?

An organization is adopting a hybrid cloud model. A security architect must document which cloud capabilities are essential to the organization's cloud reference architecture. According to the Cloud Security Alliance, which capability describes the ability to monitor, control, and audit service usage and performance across cloud environments?

A multinational corporation is designing a cloud architecture that must comply with GDPR for European customer data. The company wants to ensure that data remains within the EU and is not replicated to other regions without explicit consent. Which cloud design principle should be implemented to achieve this?

A small startup is developing a new mobile application and wants to minimize upfront infrastructure costs and management overhead. The team has limited operational expertise and prefers to focus on coding rather than managing servers. Which cloud service model is MOST appropriate for deploying the application's backend?

A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?

Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Concepts, Architecture, and Design sessions

Start a Cloud Concepts, Architecture, and Design only practice session

Every question in these sessions is drawn from the Cloud Concepts, Architecture, and Design domain — nothing else.

Related practice questions

Related CCSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCSP exam test about Cloud Concepts, Architecture, and Design?
Map data sensitivity to deployment and service models, apply shared responsibility, and evaluate provider reports and SLAs. The most important thing is correctly assigning security duties between customer and provider for the chosen model.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Concepts, Architecture, and Design questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Concepts, Architecture, and Design domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCSP topics?
Use the topic links above to move to related areas, or go back to the CCSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCSP exam covers. They are not copied from any real exam or dump site.