Cloud Architecture for Air-Gapped Security
The major business applications of an enterprise are largely monolithic and hard-coded. As part of a major modernization and overhaul of the applications, the goal is to move to a modular and containerized application architecture mode. At the same time, decoupling from the hardware is desired to move to an on-demand provisioning. However, the CyberOps team mandated that the final architecture must provide the same security levels as an air-gapped data center. Which cloud architecture meets these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the understanding of how 'air-gapped' security levels map to specific cloud deployment models, highlighting the trap of assuming hybrid or public clouds can achieve the same physical isolation.
This question evaluates the selection of a cloud deployment model that balances modernization with strict security isolation. It establishes why a private cloud is the correct choice to meet air-gapped equivalent security requirements.
Candidates often choose Hybrid Cloud (E) because they associate it with flexibility and security controls, failing to realize that true air-gapped equivalence requires the dedicated, isolated infrastructure of a Private Cloud.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Private Cloud (Option C) is the only architecture among the choices that provides the level of isolation and control necessary to replicate the security posture of an air-gapped data center. While it offers the on-demand provisioning and decoupling from hardware desired in modernization, its exclusive use by a single organization allows for strict network segmentation and physical separation, which are key characteristics of air-gapping.Why the Other Options Are Wrong
Public Cloud (D) shares infrastructure among multiple tenants, making it impossible to guarantee air-gapped-level security without significant compromises. Hybrid Cloud (E) combines public and private resources; while it offers flexibility, the public component introduces shared risks that violate the strict isolation mandate. IaaS (B) and PaaS (A) are service models, not deployment models, so they do not define the physical or logical isolation boundaries required by the question.Community Comment Notes
Community consensus strongly supports Option C, with users noting that 'air-gap' directly implies the isolation found in a private cloud. As one commenter stated, 'AIR-GAP is private cloud,' reflecting the direct mapping between the security requirement and the deployment model. Another user highlighted that no keywords forced a hybrid approach, reinforcing the logic for a dedicated private environment.Official Reference
Exam Strategy
When questions mention 'air-gapped' or 'physical isolation' alongside cloud benefits, prioritize Private Cloud over Hybrid or Public options, as these terms specifically refer to the degree of tenant isolation and physical security controls.
Frequently Asked Questions
Why isn't Hybrid Cloud suitable for air-gapped security?
Hybrid Cloud includes public cloud components that share infrastructure with other tenants, breaking the strict physical and logical isolation required for air-gapped equivalence.
Can IaaS provide air-gapped security?
IaaS is a service model, not a deployment model. It does not inherently define the isolation boundaries needed for air-gapped security, which depends on the underlying deployment (e.g., Private vs. Public).