Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?

⚠ Common exam trap

The trap here is assuming that the provider's PCI DSS attestation absolves the customer of all responsibility, when the customer must still secure its own cardholder data environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The customer is responsible for configuring and managing the guest operating system, applications, and cardholder data environment, including access controls and encryption.

Under PCI DSS in IaaS, the customer is responsible for the guest operating system, applications, and cardholder data environment, including access controls and encryption. The provider secures the physical and hypervisor layers. Each party must validate its own controls, and the customer cannot rely solely on the provider's attestation for its own compliance obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The customer is responsible only for physical security of the data center because the provider handles all logical controls.

    Why it's wrong here

    This is reversed. Physical security is typically the provider's responsibility in IaaS. The customer is responsible for logical controls within its instances, such as firewalls, encryption, and identity management. Assuming the provider handles all logical controls would leave the cardholder data environment unprotected at the guest OS and application layers, violating PCI DSS.

  • ✓

    The customer is responsible for configuring and managing the guest operating system, applications, and cardholder data environment, including access controls and encryption.

    Why this is correct

    In IaaS, the customer controls the guest OS and above, so it must implement PCI DSS requirements for those layers, such as access control, encryption of cardholder data, and vulnerability management. The provider is responsible for the physical and hypervisor layers. PCI DSS requires each party to attest to the controls it operates, and the customer cannot outsource its compliance obligations for its own cardholder data environment.

  • ✗

    The customer is responsible for nothing because the provider's PCI DSS attestation covers all systems storing cardholder data.

    Why it's wrong here

    A provider's PCI DSS attestation covers the provider's infrastructure and services, not the customer's configurations, applications, or data. The customer must still validate its own cardholder data environment, including segmentation, access controls, and encryption. Relying solely on the provider's attestation would leave the customer non-compliant and potentially liable for breaches.

  • ✗

    The customer is responsible for all PCI DSS requirements because PCI DSS does not recognize shared responsibility models.

    Why it's wrong here

    PCI DSS does recognize shared responsibility, and the PCI Security Standards Council has published guidance on cloud computing. Providers can validate their environments, and customers can inherit controls for the layers the provider manages. Stating that PCI DSS does not recognize shared responsibility is factually incorrect and would lead to unnecessary duplication and misallocation of compliance efforts.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.