Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A cloud architect is mapping security responsibilities for a SaaS customer relationship management deployment. The provider manages the application, runtime, middleware, operating system, and physical infrastructure. Which security task remains the responsibility of the customer organization?

⚠ Common exam trap

The trap here is assuming that SaaS means the provider secures everything, when the customer always retains responsibility for identity, access, and its own data handling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managing user identities, access entitlements, and authentication configuration

In every cloud service model, the customer retains responsibility for its own data governance and access management. With SaaS, the provider covers the stack from physical facilities through the application, but identity lifecycle, entitlement decisions, and authentication configuration require knowledge of the customer's personnel and business roles, so those tasks cannot be delegated to the provider.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Maintaining the physical security of the data center hosting the application

    Why it's wrong here

    Physical security controls such as perimeter defenses, badge access, surveillance, and environmental protection belong to the SaaS provider, which owns and operates the data centers. The customer has no physical presence or authority at those facilities, so this responsibility cannot be assigned to the customer under the shared responsibility model.

  • ✓

    Managing user identities, access entitlements, and authentication configuration

    Why this is correct

    Even in SaaS, the customer controls who within its organization can access the application, what roles and entitlements they hold, and how authentication integrates with its identity provider. Managing accounts, enforcing least privilege, and revoking access for departing staff remain customer duties because the provider cannot know the organization's business roles or personnel changes.

  • ✗

    Patching the operating system and runtime hosting the application

    Why it's wrong here

    In a SaaS deployment, the provider owns the operating system, runtime, and middleware layers, including patching them. The customer has no administrative access to those layers and cannot apply patches, so this task falls entirely to the provider and is not part of the customer's residual responsibility in this scenario.

  • ✗

    Applying firmware updates to the hypervisor and host servers

    Why it's wrong here

    Hypervisor and host server firmware updates are part of the provider's infrastructure management in a SaaS model. The customer lacks access to the virtualization layer and cannot perform these updates, so this is a provider responsibility that would only shift to the customer in lower-level models such as IaaS.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.