Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A cloud engineer is configuring a web application that must comply with PCI DSS. The application runs on virtual machines in a public cloud. Which of the following security responsibilities falls under the customer's scope according to the shared responsibility model?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patching the guest operating system of the virtual machines

In the shared responsibility model, the customer is responsible for patching the guest OS, while the cloud provider manages the physical infrastructure and hypervisor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replacing failed physical drives in the storage array

    Why it's wrong here

    Physical drive replacement sits with the cloud provider, which owns data-centre hardware and storage arrays; the customer never handles failed disks under the shared responsibility model. It is tempting because storage durability and PCI DSS evidence obligations feel customer-owned, yet the customer's scope covers guest OS patching, application security and data classification instead.

  • ✓

    Patching the guest operating system of the virtual machines

    Why this is correct

    Patching the guest operating system falls to the customer because infrastructure-as-a-service places OS-level maintenance squarely on the tenant, not the provider. PCI DSS requires timely security updates on systems handling cardholder data, and the hypervisor, physical hosts and network fabric remain the provider's responsibility under this model.

  • ✗

    Configuring the physical network firewall

    Why it's wrong here

    Physical network firewall configuration belongs to the cloud provider, which controls cabling, switches and edge hardware; the customer configures virtual firewalls, security groups and network ACLs instead. It is tempting because PCI DSS mandates firewalls between trusted zones, yet that obligation maps to the customer's virtual network controls, not provider-owned physical appliances.

  • ✗

    Applying hypervisor patches

    Why it's wrong here

    Hypervisor patching is performed by the cloud provider, since the hypervisor sits beneath the customer's virtual machines and is never exposed to tenants. It is tempting because patching is a recurring PCI DSS requirement, yet the customer patches guest operating systems, middleware and applications, while the provider maintains the virtualisation layer and firmware.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.