Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

According to the shared responsibility model, which of the following is the cloud provider responsible for?

⚠ Common exam trap

Watch out — candidates often confuse 'security OF the cloud' (provider) with 'security IN the cloud' (customer) — candidates often assume the provider patches everything, but OS patching and IAM remain customer duties in most service models.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Physical infrastructure security

Under the shared responsibility model, the cloud provider is always responsible for the security OF the cloud — the physical facilities, hardware, network fabric, and hypervisor layer that underpin the service. Physical infrastructure security (data center access controls, hardware disposal, environmental controls) is entirely the provider's domain and cannot be delegated to the customer. Customers are responsible for security IN the cloud, which covers their data, configurations, and workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Operating system patching

    Why it's wrong here

    Operating system patching sits with the customer in IaaS, since they control the guest OS; only in PaaS or SaaS does the provider patch beneath the application layer. It tempts because providers do patch hypervisors and managed runtimes, so patching feels shared, but the stem's model assigns guest OS updates to the consumer.

  • ✓

    Physical infrastructure security

    Why this is correct

    Under the shared responsibility model, the cloud provider owns security of the cloud: datacentre facilities, hardware, networking and physical access controls. The customer remains responsible for security in the cloud, covering guest OS patching, application configuration and identity management.

  • ✗

    Application code security

    Why it's wrong here

    Application code security stays with the customer, since the provider secures the underlying compute, storage and network layers, not the code deployed on them. It is tempting because providers supply patched runtimes and managed services; it would be correct for physical host and hypervisor security.

  • ✗

    Identity and access management configuration

    Why it's wrong here

    Identity and access management configuration remains a customer responsibility across IaaS, PaaS and SaaS; the provider secures only the identity platform's infrastructure. It tempts because Microsoft Entra ID is operated by Microsoft, yet tenants still configure roles, conditional access and permissions themselves, so the duty never transfers.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.