CEH Shared Responsibility Model Practice Question
Which TWO of the following correctly describe aspects of the shared responsibility model in cloud computing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer is responsible for securing data stored in the cloud
In the shared responsibility model, the customer is responsible for security IN the cloud (e.g., data, application configurations, identity management) while the provider is responsible for security OF the cloud (e.g., physical security, network infrastructure). Option C is correct because customers must secure their stored data. Option E is correct because providers secure data center physical access. Option A is incorrect: the cloud provider does not manage customer encryption keys; that is the customer's responsibility. Option B is incorrect: in PaaS, the provider manages the network firewall; the customer manages application-level security only. Option D is incorrect: in IaaS, the customer patches the guest OS; the provider patches the hypervisor and physical infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloud provider is responsible for managing customer application encryption keys
Why it's wrong here
In the shared responsibility model, customers retain ultimate control and responsibility for their application encryption keys, especially when dealing with sensitive data. While cloud providers often offer Key Management Services (KMS) to facilitate key generation, storage, and rotation, these services typically operate under the customer's administrative control and policy definitions. The provider secures the KMS infrastructure, but the customer dictates key usage and access.
- ✗
The customer is responsible for network firewall configuration in PaaS
Why it's wrong here
For Platform as a Service (PaaS) offerings, the cloud provider assumes responsibility for the underlying network infrastructure, including its firewalls, routing, and overall security. Customers in a PaaS model are abstracted from these lower-level network configurations, focusing instead on their application code, data, and application-level security settings. The provider ensures the network environment is secure and operational.
- ✓
The customer is responsible for securing data stored in the cloud
Why this is correct
Regardless of the cloud service model (IaaS, PaaS, SaaS), the customer always retains primary responsibility for the security of their data itself. This encompasses implementing appropriate encryption for data at rest and in transit, configuring robust access controls and identity management, and ensuring data integrity and compliance. The cloud provider secures the underlying infrastructure that stores the data, but the data's content security is the customer's domain.
- ✗
The cloud provider is responsible for patching the guest operating system in IaaS
Why it's wrong here
In an Infrastructure as a Service (IaaS) model, the customer is explicitly responsible for managing and patching the guest operating system (OS) running on their virtual machines. The cloud provider's responsibility in IaaS extends only to the underlying physical infrastructure, hypervisor, and network fabric. Customers must ensure their OS, applications, and middleware are kept up-to-date with security patches.
- ✓
The cloud provider is responsible for physical security of data centers
Why this is correct
Cloud providers are unequivocally responsible for the physical security of their data centers, which house the servers, networking equipment, and storage infrastructure. This includes implementing stringent access controls, surveillance systems, environmental controls, and disaster recovery measures to protect the physical assets from unauthorized access, theft, or damage. This foundational layer of security is entirely managed by the provider.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.