CV0-004 Security Practice Question
A cloud operations team is reviewing the shared responsibility model for a SaaS customer relationship management application. The team wants to document which security tasks remain the customer's responsibility. Which task is the customer responsible for under the shared responsibility model?
⚠ Common exam trap
The trap here is conflating infrastructure-layer duties such as hypervisor or firmware patching with customer duties, which in SaaS are limited to data and identity governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user identities, access permissions, and authentication policies within the SaaS application.
Under the shared responsibility model, the provider secures the cloud infrastructure while the customer secures what they put in the cloud. For SaaS, that means the customer owns data classification, user identity, access management, and authentication configuration. Physical security, hypervisor patching, and hardware firmware all fall to the provider because they sit below the customer's reach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patching the hypervisor that hosts the SaaS application's virtual machines.
Why it's wrong here
Hypervisor patching is performed by the cloud provider because the hypervisor sits below the abstraction boundary the customer never touches. In a SaaS deployment, the provider manages the entire physical and virtualization stack. Assigning this to the customer would be technically impossible and would violate the division of responsibilities defined by the provider's compliance documentation.
- ✓
Managing user identities, access permissions, and authentication policies within the SaaS application.
Why this is correct
Identity and access management for the customer's own users remains a customer responsibility in every cloud service model, including SaaS. The provider secures the application infrastructure, but the customer decides who can log in, what roles they hold, and how authentication is enforced. Weak access controls on the customer side are a leading cause of SaaS data breaches.
- ✗
Maintaining the physical security controls at the data center hosting the SaaS platform.
Why it's wrong here
Physical security of data centers is always the cloud provider's responsibility. Customers have no access to provider facilities and cannot implement badge controls, guards, or perimeter defenses there. Providers publish independent audit reports covering these controls, and customers rely on those attestations rather than performing the work themselves.
- ✗
Applying firmware updates to the storage arrays that back the SaaS application's database.
Why it's wrong here
Storage array firmware is part of the provider-managed infrastructure layer. The customer has no visibility into or control over the underlying hardware in a SaaS model. The provider schedules and applies firmware updates as part of maintaining platform availability and security, and customers consume the resulting service without direct involvement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.