CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
In the shared responsibility model for cloud computing, which of the following is typically the customer's responsibility?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuration of IAM roles and permissions
The customer is responsible for security IN the cloud, including configuring IAM policies, encryption, and access controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical security of data centers
Why it's wrong here
In the shared responsibility model, the cloud provider is solely accountable for the physical security of data centers. This includes implementing robust physical access controls, surveillance systems, environmental controls like HVAC and fire suppression, and ensuring the structural integrity of the facilities where cloud infrastructure resides. Customers have no direct control or responsibility over these foundational physical security measures.
- ✗
Hypervisor security
Why it's wrong here
The security of the hypervisor, which is the virtualization layer managing virtual machines, falls squarely within the cloud provider's domain. The provider is responsible for patching, hardening, and configuring the hypervisor to prevent vulnerabilities and ensure the secure isolation of customer instances. This critical component ensures the integrity and separation of workloads running on the shared underlying physical hardware.
- ✗
Network infrastructure security
Why it's wrong here
The cloud provider is responsible for the security of the underlying network infrastructure, encompassing the physical network hardware, cabling, routers, switches, and core network services that facilitate connectivity within their cloud environment. This includes protecting against network-level attacks like DDoS at the network edge and ensuring the availability and integrity of the foundational network fabric. Customers, however, are responsible for securing their own virtual networks and network configurations within the cloud.
- ✓
Configuration of IAM roles and permissions
Why this is correct
Customers are directly responsible for the configuration of Identity and Access Management (IAM) roles and permissions within their cloud environment. This involves defining users, groups, and roles, assigning appropriate permissions based on the principle of least privilege, and regularly auditing access policies. Proper IAM configuration is critical for controlling who can access what resources and is a primary customer security control.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.