Courseiva
mediumMultiple Choice

CCSP Practice Question: A company uses a cloud provider's managed…

A company uses a cloud provider's managed database service. The security team is concerned about the shared responsibility model for patching the operating system and database engine. According to the shared responsibility model, who is responsible for applying security patches to the database engine?

⚠ Common exam trap

CCSP often tests the shared responsibility model by blurring the line between configuration responsibility and patching responsibility — candidates may think that because they control database configuration, they also patch the engine, which is false for managed services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cloud provider, because it is a managed service

In the cloud shared responsibility model, for a managed database service (such as Amazon RDS or Azure SQL Database), the cloud provider is responsible for patching the underlying operating system and the database engine. The customer is responsible for data, access management, and configuration within the database, but not for engine patching. Therefore the cloud provider applies security patches to the database engine (option C).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The customer, because they control the database configuration

    Why it's wrong here

    The customer configures the database but does not patch the engine, which the provider operates within its managed service. It tempts because customers patch self-managed databases on IaaS, yet here the provider owns the engine layer under the shared responsibility model.

  • ✗

    A third-party vendor contracted by the customer

    Why it's wrong here

    In a managed database service the provider patches the database engine, so no third party is involved; the customer only patches what it controls, such as data and access. Contracting an external vendor is tempting when self-managed databases run on IaaS, where the customer owns OS and engine patching.

  • ✓

    The cloud provider, because it is a managed service

    Why this is correct

    In a managed database service, the provider operates the underlying infrastructure and database engine, so patching that engine falls to them under the shared responsibility model. The customer retains responsibility only for data, access and configuration.

  • ✗

    Both the customer and the cloud provider equally

    Why it's wrong here

    Responsibility is not split equally; the provider patches the database engine because it operates the managed platform. It tempts as a compromise when teams assume shared responsibility means joint effort, but the split follows control of the underlying layer, not equal division.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.