Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A cloud architect is designing a multi-tier application that will be deployed in a public cloud. The application must meet strict security and compliance requirements, including data isolation, network segmentation, and encryption of data at rest and in transit. The architect is considering using a virtual private cloud (VPC) and must ensure that the design aligns with the cloud shared responsibility model. Which TWO of the following are the cloud customer's responsibilities under the shared responsibility model? (Choose two.)

⚠ Common exam trap

Many candidates confuse the provider's responsibility for physical security and hypervisor management with the customer's responsibility for securing their own data and network configurations. Many candidates incorrectly assume the provider handles all aspects of security, including data encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypting application data at rest using customer-managed keys.

Under the shared responsibility model for IaaS, the customer is responsible for security in the cloud, which includes configuring network controls (security groups, network ACLs) and encrypting data at rest with customer-managed keys. The provider is responsible for security of the cloud, including physical security, hypervisor patching, and physical network redundancy. Therefore, the customer's responsibilities are configuring security groups and network ACLs, and encrypting application data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring the physical network infrastructure is redundant and fault-tolerant.

    Why it's wrong here

    Ensuring the physical network infrastructure is redundant and fault-tolerant is a responsibility of the cloud service provider. The customer relies on the provider's network architecture for physical redundancy. In a public cloud, the customer is responsible for designing redundancy at the application and virtual network level, but not for the physical network components.

  • ✗

    Managing the physical security of the data center where the application is hosted.

    Why it's wrong here

    Physical security of the data center is the responsibility of the cloud service provider, not the customer. Under the shared responsibility model, the provider is responsible for the security of the cloud, which includes physical facilities, hardware, and the hypervisor. The customer does not have access to or control over the physical environment in a public cloud.

  • ✓

    Encrypting application data at rest using customer-managed keys.

    Why this is correct

    The customer is responsible for encrypting their data at rest, including choosing and managing encryption keys. While the cloud provider may offer encryption capabilities and key management services, the customer must configure and manage the encryption of their own data. This includes using customer-managed keys (CMKs) to maintain control over access to the data.

  • ✓

    Configuring security groups and network ACLs to control traffic to and from the application instances.

    Why this is correct

    In a public cloud IaaS environment, the customer is responsible for securing the guest operating system, applications, and network controls such as security groups and network ACLs. These are considered part of the customer's responsibility because they involve configuration and management of the virtual network and instances. The cloud provider secures the underlying infrastructure but not the customer's specific network traffic rules.

  • ✗

    Patching the hypervisor and underlying host operating system.

    Why it's wrong here

    Patching the hypervisor and underlying host operating system is the responsibility of the cloud service provider. The customer does not have access to the hypervisor or the host OS in a public cloud IaaS environment. The provider is responsible for maintaining and patching the virtualization layer and physical hosts to ensure the security and stability of the cloud platform.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.