SY0-701 Security Architecture Practice Question
A development team deploys a Linux web server on an IaaS cloud VM. The cloud provider secures the datacenter, hardware, and hypervisor. Which control remains the organization's responsibility?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply OS patches and harden services running inside the virtual machine.
In an IaaS model, the provider handles the physical infrastructure, storage, networking foundation, and hypervisor layer. The customer remains responsible for what runs on the VM, including the guest operating system, services, configuration, and application patching. Hardening the server inside the VM is therefore the correct answer because it is one of the core customer responsibilities in this cloud model. Why others are wrong: Physical badge access and hypervisor patching are provider duties in IaaS, so the customer cannot rely on those as their own control. Replacing the provider backbone is outside the scope of the customer’s operational responsibility and is not how shared responsibility works. The question asks for the organization’s remaining duty, which is securing the guest OS and its applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Monitor physical badge access at the provider facility.
Why it's wrong here
In an IaaS model, the cloud provider is exclusively responsible for the physical security of its data centers, including badge access, surveillance, and perimeter controls. The customer's responsibilities begin at the virtualization layer, meaning that monitoring facility access is outside the customer's administrative scope and requires access to provider-owned systems that are not exposed to the customer. Attempting to perform such monitoring would be operationally impossible and would breach the clear boundary set by the shared responsibility model.
- ✓
Apply OS patches and harden services running inside the virtual machine.
Why this is correct
Under IaaS, the customer retains full administrative control of the guest operating system and all software running inside the virtual machine, which carries the obligation to apply security patches and harden services. This includes updating the OS kernel and installed packages, disabling unnecessary daemons, configuring host-based firewalls, and enforcing least-privilege access to the VM. The provider does not have visibility or responsibility for the guest OS, so any unpatched vulnerability or weak service configuration inside the VM is solely the customer's risk.
- ✗
Replace the provider's network backbone with a private carrier circuit.
Why it's wrong here
The provider's network backbone is an integral part of the cloud infrastructure that interconnects physical hosts, availability zones, and regions, and it is owned and managed entirely by the provider. A customer cannot replace or physically alter this backbone because they do not have access to the provider's internal networking hardware or control plane. While customers can order dedicated private connectivity options like Direct Connect or ExpressRoute, these services attach to the provider's edge and do not change or replace the underlying backbone infrastructure.
- ✗
Ensure the hypervisor is updated before every release cycle.
Why it's wrong here
Hypervisor maintenance and patching are explicitly the cloud provider's responsibility in a standard IaaS shared responsibility model, as the hypervisor is part of the virtualization layer that the customer never directly accesses. The provider ensures that hypervisor updates are tested and applied to maintain tenant isolation and fix underlying virtualization vulnerabilities, so the customer cannot and should not attempt to manage these updates. In contrast, the customer's patching duty is limited to the guest OS and applications residing inside the virtual machine, not the virtualization platform itself.
Go deeper
Related to this question
Learn chapter
Cloud Security Fundamentals
Key term
Hypervisor
A hypervisor is software that creates and runs virtual machines by allowing multiple operating systems to share a single hardware host.
Key term
Hardening
Hardening is the process of securing a computer system or network by reducing its attack surface, disabling unnecessary services, and applying security configurations.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.