Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

A team runs a confidential document repository on an IaaS virtual machine. The cloud provider secures the datacenter, hardware, and hypervisor. Which task remains the organization’s responsibility?

⚠ Common exam trap

Test-takers frequently confuse the IaaS shared responsibility model with PaaS or SaaS, where the provider handles more of the stack; candidates often assume the provider patches the guest OS or manages application access, but in IaaS those are customer responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Hardening the guest operating system and controlling access to the repository application.

In an IaaS model, the cloud provider is responsible for the security of the cloud (physical datacenter, hardware, hypervisor), while the customer is responsible for security in the cloud. This includes hardening the guest OS, configuring firewalls, managing access controls, and patching the operating system and applications. Option C correctly identifies the organization's duty to secure the guest OS and the repository application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Patching the physical hosts inside the cloud provider's datacenter.

    Why it's wrong here

    In an IaaS shared responsibility model, the cloud provider is exclusively responsible for the underlying physical hosts, including firmware, hardware, and the host operating system. Patching these hosts requires administrative access to the provider's datacenter infrastructure, which is not granted to tenants. Customers are expected to patch only their guest operating systems and applications. This task is provider-owned, not a customer responsibility.

  • Replacing the provider's hypervisor when a new version is released.

    Why it's wrong here

    The hypervisor is the virtualization layer that the provider installs, configures, and maintains to run customer VMs. A tenant in IaaS has no access to the hypervisor and no authority to replace it when a new version is released; doing so would compromise the provider's multi-tenant control plane. Upgrades and patches to the hypervisor are scheduled by the provider, often with maintenance windows that may affect VM performance. Replacing the hypervisor is fundamentally outside the customer's shared responsibility boundary.

  • Hardening the guest operating system and controlling access to the repository application.

    Why this is correct

    In IaaS, the organization is responsible for what it deploys on the virtual machine, including the guest operating system, its configuration, patching, and application-level access controls. Those tasks directly affect who can use the document repository and how securely the workload runs. Shared responsibility means the provider handles the platform, while the customer secures the OS and data-layer usage.

  • Managing the cloud provider's physical badge access for the server room.

    Why it's wrong here

    Physical badge access to the provider's server rooms is part of facility security, which sits entirely on the provider side of the shared responsibility model. IaaS customers have no credentials, policies, or contracts to provision or modify those physical access controls; they can only rely on provider assurances such as SOC 2 reports. Meanwhile, the customer is accountable for logical access, like configuring identity and access management and network firewalls. Managing physical badges is neither possible nor necessary for the customer.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.