CCSP Cloud Concepts, Architecture, and Design Practice Question
A cloud architect is evaluating a public cloud provider for a regulated workload. The provider offers a shared responsibility model. Which TWO of the following are typically the cloud customer's responsibilities under that model? (Choose two.)
⚠ Common exam trap
The trap here is assuming the provider secures everything, when the customer still owns identity configuration and data protection even in a public cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring identity and access management policies
Under the shared responsibility model, the customer is responsible for security in the cloud, which includes configuring identity and access management policies and classifying and protecting data. Physical access, hypervisor patching, and physical network fabric are provider responsibilities. Regulated workloads require the customer to focus on data protection and access control while relying on the provider for infrastructure security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configuring identity and access management policies
Why this is correct
Identity and access management policies are configured by the customer to control who can access their resources and data. The provider secures the underlying identity platform, but the customer defines users, roles, permissions, and federation. This is a core customer responsibility in public cloud, especially for regulated workloads where least privilege must be enforced.
- ✗
Maintaining the physical network fabric between availability zones
Why it's wrong here
The physical network fabric connecting availability zones is owned and maintained by the cloud provider. Customers do not manage routers, switches, or cabling in the provider's backbone. This option incorrectly assigns infrastructure responsibilities to the customer. It is a provider duty in public cloud.
- ✓
Classifying and protecting data stored in the cloud
Why this is correct
Data classification and protection, including encryption, access controls, and retention, remain the customer's responsibility. The provider offers tools, but the customer decides what data is sensitive and how it is safeguarded. In regulated environments, this is critical for compliance. Therefore, this is a correct customer responsibility under the shared responsibility model.
- ✗
Patching the hypervisor
Why it's wrong here
Hypervisor patching is the provider's responsibility in a public cloud because the hypervisor is part of the managed infrastructure. Customers do not have access to patch the hypervisor. Assigning this to the customer would be incorrect and could lead to security gaps if attempted. The provider handles virtualization layer maintenance.
- ✗
Managing physical access to the data center
Why it's wrong here
Physical access to the data center is almost always the cloud provider's responsibility in a public cloud. The provider controls facilities, hardware, and environmental controls. The customer does not manage physical access, so this option is incorrect. Confusing physical security with customer duties is a common misunderstanding of the shared responsibility model.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.