Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

⚠ Common exam trap

The trap is confusing the responsibilities of the cloud provider and customer, often assuming the provider handles more than they do, such as OS patching in IaaS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patching the guest operating system

In an IaaS deployment, the customer is responsible for patching the guest operating system (A). Under the shared responsibility model, the cloud provider manages the physical security, network infrastructure, and hypervisor, while the customer is responsible for the security of everything they deploy on the infrastructure, including the guest OS, applications, and data. Patching the guest OS is a customer task because the customer has control over the OS and its configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Patching the guest operating system

    Why this is correct

    In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching the guest OS therefore remains the customer's responsibility, unlike PaaS or SaaS where the provider handles it.

  • ✗

    Network infrastructure security

    Why it's wrong here

    The provider owns the routers, switches and interconnects forming the cloud network fabric; customers secure only their own virtual network configuration, security groups and traffic. It is tempting because customers do manage VPC subnets and firewall rules, but the underlying network infrastructure security remains with the provider.

  • ✗

    Physical security of data centers

    Why it's wrong here

    Data-centre buildings, cages, power and cooling are owned and operated by the provider, so physical security never transfers to the customer under IaaS. It is tempting because customers still secure physical access to their own on-premises hardware, but in public cloud that responsibility ends at the provider's perimeter.

  • ✗

    Hypervisor security

    Why it's wrong here

    The hypervisor sits beneath the guest OS and is operated by the cloud provider, so securing it falls outside the customer's IaaS boundary. It is tempting because customers do control guest OS patching and some virtualisation settings, but the hypervisor layer itself remains provider-managed alongside the physical hosts.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.