Courseiva
easyMultiple ChoiceObjective-mapped

Cloud Digital Leader Practice Question: Is planning to adopt cloud services but needs to…

An organization is planning to adopt cloud services but needs to understand which party is responsible for physical security of the data center. Under the shared responsibility model, who is responsible for physical data center security in a public cloud deployment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The cloud provider, who is entirely responsible for all physical security of data center facilities and hardware

In the cloud shared responsibility model, physical security of data centers — including building access controls, perimeter security, surveillance, and hardware security — is always the sole responsibility of the cloud provider. Customers never have physical access to cloud provider data centers and bear no responsibility for physical security. This is one of the fundamental security benefits of using a public cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The customer, because they own the data stored in the data center

    Why it's wrong here

    The customer's ownership of data stored in the cloud gives them legal rights over that data, but it does not extend to physical security obligations. In the shared responsibility model, the customer is accountable for data classification, encryption, and access management, while the provider is exclusively accountable for the physical data center. Since the customer has no physical presence or access, they cannot be responsible for facility controls.

  • A shared responsibility: the cloud provider secures the building exterior while the customer secures the server racks

    Why it's wrong here

    This split mischaracterizes the shared responsibility model by dividing physical security spatially. In a public cloud data center, customers never have physical access to server racks, so they cannot possibly secure them. The actual division is between physical controls (provider) and logical/data controls (customer), such as guest OS, network configuration, and application security. Both layers may involve the same hardware, but only the provider controls the physical environment.

  • The cloud provider, who is entirely responsible for all physical security of data center facilities and hardware

    Why this is correct

    The cloud provider is entirely responsible for all physical security controls within its data centers, including perimeter protections, biometric access systems, guards, CCTV, and environmental safeguards like fire suppression and cooling. This is one of the clearest divisions in the shared responsibility model: customer responsibilities begin at the hypervisor and workloads, not at the physical layer. The provider also monitors hardware integrity and manages the lifecycle of servers to prevent tampering, ensuring the physical foundation for customer workloads.

  • A third-party security company contracted by both the customer and the cloud provider

    Why it's wrong here

    Although cloud providers often engage third-party security firms to carry out guarding or monitoring, the provider remains solely responsible for physical security under the shared model. The customer has no contractual relationship with such vendors and is never a party to their agreements. Any liability for a physical breach or failure still falls on the provider, who must ensure the contracted vendor meets required security standards. Thus, the customer cannot delegate or share this responsibility with a third party.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.