Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A financial services company is migrating its cardholder data environment to a public cloud IaaS platform. The security team must determine which controls remain the customer's responsibility under the shared responsibility model. Which of the following is the customer's responsibility in this IaaS deployment?

⚠ Common exam trap

The trap here is assuming that because the provider manages the platform, it also patches the guest operating system, when in IaaS the customer always owns everything from the OS upward.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patching the guest operating system and its installed applications

Under the shared responsibility model for IaaS, the provider owns security of the cloud, including facilities, hardware, and the hypervisor, while the customer owns security in the cloud. That includes the guest operating system, runtime, applications, and data. Because the question concerns a cardholder data environment, the customer must demonstrate patch management for the guest OS and applications as part of PCI DSS compliance obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Maintaining the physical security controls of the data center housing the hosts

    Why it's wrong here

    Physical security of the facilities, including badge access, cameras, and environmental controls, is owned and operated by the cloud provider in every public IaaS offering. The customer cannot implement or audit these controls directly and instead relies on provider attestations such as SOC 2 reports. Attempting to claim this as a customer responsibility misreads the shared responsibility division of labor.

  • ✗

    Managing the redundancy of the physical network switches that interconnect racks

    Why it's wrong here

    Physical network redundancy inside the provider's data center is a provider-managed resilience control. Customers configure logical networking such as VPCs, subnets, and route tables, but they never touch the physical switch fabric. Confusing logical network configuration with physical infrastructure management is a common error when mapping shared responsibility boundaries in IaaS contracts.

  • ✓

    Patching the guest operating system and its installed applications

    Why this is correct

    In IaaS the provider secures the physical hosts, hypervisor, and network fabric, while the customer retains full control and responsibility for the guest operating system, middleware, and applications running on top of it. Patching the guest OS in the cardholder environment is therefore squarely a customer duty, and auditors will expect documented patch management evidence for those instances.

  • ✗

    Applying firmware and microcode updates to the underlying hypervisor hosts

    Why it's wrong here

    The hypervisor and its host firmware sit below the abstraction boundary and are exclusively managed by the cloud provider. Customers have no administrative access to these layers, so they cannot patch them even if they wanted to. This control belongs to the provider and is typically covered under its compliance certifications rather than the customer's own control matrix.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.