Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A company is migrating a legacy application to a cloud provider's infrastructure as a service (IaaS) platform. The security team must ensure that the hypervisor layer is patched and secured, and that tenants cannot access each other's memory or storage. According to the shared responsibility model, which party is responsible for securing the hypervisor and preventing cross-tenant access?

⚠ Common exam trap

The trap here is assuming that IaaS gives the customer responsibility for all layers, when the hypervisor and physical infrastructure always remain with the cloud provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cloud provider, because the hypervisor and underlying infrastructure are part of the provider's managed security scope.

The cloud provider is responsible for securing the hypervisor and preventing cross-tenant access because these are part of the provider's managed infrastructure. Customers cannot access or patch the hypervisor in IaaS. The shared responsibility model always assigns the hypervisor, physical hosts, and network fabric to the provider, while the customer secures the guest OS, applications, and data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The cloud provider, because the hypervisor and underlying infrastructure are part of the provider's managed security scope.

    Why this is correct

    In the shared responsibility model, the cloud provider is always responsible for the security of the cloud, which includes the hypervisor, physical hosts, and the network fabric. The provider patches and secures the hypervisor and enforces tenant isolation. The customer cannot perform these tasks in IaaS, so the provider must own them. This is the correct division of responsibility.

  • ✗

    A third-party auditor, because independent verification is required to ensure tenant isolation in multi-tenant environments.

    Why it's wrong here

    Third-party auditors may verify controls, but they do not secure the hypervisor or prevent cross-tenant access. Security implementation remains with the cloud provider. Auditors provide assurance, not operational security. This option confuses assurance activities with operational responsibility, which is a common misconception but incorrect for this scenario.

  • ✗

    The customer, because they are responsible for all security controls in IaaS.

    Why it's wrong here

    In IaaS, the customer is responsible for the guest operating system, applications, and data, but not for the hypervisor or the physical infrastructure. The customer cannot patch or secure the hypervisor because they do not have access to it. Claiming full customer responsibility for all controls in IaaS misinterprets the shared responsibility model, which always reserves the hypervisor for the provider.

  • ✗

    Both parties share equal responsibility, with the customer patching the hypervisor and the provider monitoring for cross-tenant attacks.

    Why it's wrong here

    The customer does not have access to the hypervisor in IaaS, so they cannot patch it. Equal responsibility for hypervisor patching is not feasible. While both parties have distinct roles, the hypervisor is exclusively the provider's responsibility. This option misstates the shared responsibility model by assigning an impossible task to the customer.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.