Courseiva

CEH Shared Responsibility Model Practice Question

Which TWO of the following correctly describe aspects of the shared responsibility model in cloud computing?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The customer is responsible for securing data stored in the cloud

In the shared responsibility model, the customer is responsible for security IN the cloud (e.g., data, application configurations, identity management) while the provider is responsible for security OF the cloud (e.g., physical security, network infrastructure). Option C is correct because customers must secure their stored data. Option E is correct because providers secure data center physical access. Option A is incorrect: the cloud provider does not manage customer encryption keys; that is the customer's responsibility. Option B is incorrect: in PaaS, the provider manages the network firewall; the customer manages application-level security only. Option D is incorrect: in IaaS, the customer patches the guest OS; the provider patches the hypervisor and physical infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The cloud provider is responsible for managing customer application encryption keys

    Why it's wrong here

    In the shared responsibility model, customers retain ultimate control and responsibility for their application encryption keys, especially when dealing with sensitive data. While cloud providers often offer Key Management Services (KMS) to facilitate key generation, storage, and rotation, these services typically operate under the customer's administrative control and policy definitions. The provider secures the KMS infrastructure, but the customer dictates key usage and access.

  • The customer is responsible for network firewall configuration in PaaS

    Why it's wrong here

    For Platform as a Service (PaaS) offerings, the cloud provider assumes responsibility for the underlying network infrastructure, including its firewalls, routing, and overall security. Customers in a PaaS model are abstracted from these lower-level network configurations, focusing instead on their application code, data, and application-level security settings. The provider ensures the network environment is secure and operational.

  • The customer is responsible for securing data stored in the cloud

    Why this is correct

    Regardless of the cloud service model (IaaS, PaaS, SaaS), the customer always retains primary responsibility for the security of their data itself. This encompasses implementing appropriate encryption for data at rest and in transit, configuring robust access controls and identity management, and ensuring data integrity and compliance. The cloud provider secures the underlying infrastructure that stores the data, but the data's content security is the customer's domain.

  • The cloud provider is responsible for patching the guest operating system in IaaS

    Why it's wrong here

    In an Infrastructure as a Service (IaaS) model, the customer is explicitly responsible for managing and patching the guest operating system (OS) running on their virtual machines. The cloud provider's responsibility in IaaS extends only to the underlying physical infrastructure, hypervisor, and network fabric. Customers must ensure their OS, applications, and middleware are kept up-to-date with security patches.

  • The cloud provider is responsible for physical security of data centers

    Why this is correct

    Cloud providers are unequivocally responsible for the physical security of their data centers, which house the servers, networking equipment, and storage infrastructure. This includes implementing stringent access controls, surveillance systems, environmental controls, and disaster recovery measures to protect the physical assets from unauthorized access, theft, or damage. This foundational layer of security is entirely managed by the provider.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.