Courseiva
Legal, Risk, and Compliance →mediumMultiple Select

CCSP Legal, Risk, and Compliance Practice Question

A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)

⚠ Common exam trap

The trap here is assuming the provider handles all security controls, when data classification, IAM, and customer-managed encryption keys remain customer responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Securing the physical facilities, hardware, and network infrastructure that host the cloud services.

In a cloud shared responsibility model, the provider secures the infrastructure that delivers the service, including physical facilities, hardware, and the virtualization layer that isolates tenants. The customer remains responsible for its data, identity management, and customer-side encryption key custody. Understanding this division is essential for meeting regulatory obligations in any jurisdiction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Securing the physical facilities, hardware, and network infrastructure that host the cloud services.

    Why this is correct

    The provider owns and operates the underlying data centers, servers, and network fabric, so it is responsible for physical security, hardware maintenance, and infrastructure-level network controls. These are foundational controls that customers cannot implement themselves and form the provider's side of the shared responsibility model.

  • ✗

    Configuring encryption for the customer's data at rest using customer-managed keys stored in the customer's environment.

    Why it's wrong here

    When encryption uses customer-managed keys held in the customer's environment, the customer controls key lifecycle, access policies, and rotation. The provider may supply the encryption capability, but the configuration and key custody are the customer's responsibility, not the provider's.

  • ✗

    Classifying the customer's data and determining which regulatory requirements apply to that data.

    Why it's wrong here

    Data classification and determining applicable regulations depend on the customer's business context, data types, and jurisdictions. The provider cannot know what data the customer stores or what legal obligations attach to it. This responsibility remains with the customer, even though the provider may offer tools to support classification.

  • ✓

    Providing the hypervisor, storage virtualization, and network isolation controls that separate tenant environments.

    Why this is correct

    Multi-tenancy isolation is implemented at the hypervisor, storage, and network layers by the provider. Customers rely on these controls to prevent lateral movement between tenants. This is a core provider responsibility because customers have no visibility or administrative control over the underlying virtualization and network segregation mechanisms.

  • ✗

    Managing the customer's identity and access policies for the customer's own users and applications.

    Why it's wrong here

    Identity and access management for the customer's users, roles, and applications is configured and governed by the customer. The provider supplies the IAM service and its security, but the customer decides who gets access, what policies apply, and how credentials are managed within its tenant.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.