CV0-004 Security Practice Question
A company is migrating its on-premises applications to a public cloud. The security team wants to ensure that the cloud provider is responsible for physical security of data centers, while the company remains responsible for securing guest operating systems. Which concept does this describe?
⚠ Common exam trap
CV0-004 often tests the confusion between the shared responsibility model and other security concepts like least privilege or defense in depth, expecting candidates to identify the model that explicitly divides responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared responsibility model
The shared responsibility model defines the division of security responsibilities between the cloud provider and the customer. The provider is responsible for security 'of' the cloud (e.g., physical data centers), while the customer is responsible for security 'in' the cloud (e.g., guest OS, applications). This matches the scenario where the provider handles physical security and the company secures guest operating systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege principle
Why it's wrong here
Least privilege governs granting identities only the access they need, not splitting security duties between provider and tenant. It is tempting because cloud security discussions often begin with IAM scoping, and it would be correct when designing role assignments or permission boundaries for workloads and administrators.
- ✗
Zero Trust architecture
Why it's wrong here
Zero Trust removes implicit network trust through continuous verification, which does not define the provider-tenant split for physical facilities versus guest operating systems. It is tempting because it dominates cloud security guidance, and it would be correct when designing identity-aware access for remote users and hybrid workloads.
- ✓
Shared responsibility model
Why this is correct
The shared responsibility model splits security duties by layer: the provider secures the physical data centres, hardware and hypervisor, while the customer secures everything above, including guest operating systems, patches and identity. This directly satisfies the stem's requirement that the company retains guest OS responsibility while the provider handles physical security.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls, but it does not allocate responsibility for physical data-centre security to the provider and guest OS patching to the tenant. It is tempting because cloud security guidance stresses layered controls, and it would be correct when designing overlapping network, host and identity safeguards.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.