CV0-004 Security Practice Question
According to the shared responsibility model, which of the following is the cloud provider responsible for?
⚠ Common exam trap
Watch out — candidates often confuse 'security OF the cloud' (provider) with 'security IN the cloud' (customer) — candidates often assume the provider patches everything, but OS patching and IAM remain customer duties in most service models.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physical infrastructure security
Under the shared responsibility model, the cloud provider is always responsible for the security OF the cloud — the physical facilities, hardware, network fabric, and hypervisor layer that underpin the service. Physical infrastructure security (data center access controls, hardware disposal, environmental controls) is entirely the provider's domain and cannot be delegated to the customer. Customers are responsible for security IN the cloud, which covers their data, configurations, and workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Operating system patching
Why it's wrong here
Operating system patching sits with the customer in IaaS, since they control the guest OS; only in PaaS or SaaS does the provider patch beneath the application layer. It tempts because providers do patch hypervisors and managed runtimes, so patching feels shared, but the stem's model assigns guest OS updates to the consumer.
- ✓
Physical infrastructure security
Why this is correct
Under the shared responsibility model, the cloud provider owns security of the cloud: datacentre facilities, hardware, networking and physical access controls. The customer remains responsible for security in the cloud, covering guest OS patching, application configuration and identity management.
- ✗
Application code security
Why it's wrong here
Application code security stays with the customer, since the provider secures the underlying compute, storage and network layers, not the code deployed on them. It is tempting because providers supply patched runtimes and managed services; it would be correct for physical host and hypervisor security.
- ✗
Identity and access management configuration
Why it's wrong here
Identity and access management configuration remains a customer responsibility across IaaS, PaaS and SaaS; the provider secures only the identity platform's infrastructure. It tempts because Microsoft Entra ID is operated by Microsoft, yet tenants still configure roles, conditional access and permissions themselves, so the duty never transfers.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.