SY0-701 Security Architecture Practice Question
A company runs a Linux virtual machine in an IaaS cloud service. The provider secures the physical datacenter and hypervisor. Which task remains the company's responsibility?
⚠ Common exam trap
It's easy for candidates to confuse the shared responsibility model and assume the cloud provider handles all security tasks, including guest OS patching, when in fact the customer is responsible for anything above the hypervisor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patching the guest operating system on the virtual machine.
In an IaaS cloud model, the provider is responsible for the physical infrastructure, including the datacenter, network, storage, and hypervisor. The customer retains responsibility for securing the guest operating system, including applying patches and updates. Patching the guest OS is a shared responsibility that falls squarely on the company operating the virtual machine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Patching the guest operating system on the virtual machine.
Why this is correct
In an IaaS model, the organization still manages what runs inside the VM, including the guest operating system, patches, applications, and configuration. The cloud provider secures the underlying facility, hardware, and hypervisor, but it does not maintain the customer's OS or application stack. Keeping the guest OS patched is essential to reduce exposure to known vulnerabilities and aligns with the shared responsibility model.
- ✗
Replacing failed physical storage drives in the provider's data center.
Why it's wrong here
Physical storage drives are part of the cloud provider's infrastructure layer in an IaaS offering. The customer only sees a virtual disk attached to a VM; the underlying RAID controllers, SSDs, and their replacement are managed entirely by the provider. Because the tenant has no physical access to the data center, replacing a failed drive is both impossible and outside the customer's scope under the shared responsibility model.
- ✗
Hardening the hypervisor that hosts the cloud tenant.
Why it's wrong here
The hypervisor is the provider-managed software layer that isolates and runs all customer VMs on shared hardware. In IaaS, the customer has no administrative or console access to that hypervisor; therefore any security hardening, patching, or configuration of it must be performed by the cloud provider. The tenant's responsibility begins at the guest OS, not at the virtualization boundary.
- ✗
Controlling badge access to the cloud vendor's server room.
Why it's wrong here
Badge access control to a server room is a physical security control that belongs exclusively to the cloud data center operator. The IaaS customer never enters the vendor's facility and has no ability to alter its access-control systems, such as card readers or visitor logs. Physical safeguards are the provider's obligation under the shared responsibility model, leaving the tenant to focus on logical and virtualized security.
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.