Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A healthcare organization is migrating patient records to a public cloud provider. Which of the following is the most critical consideration regarding shared responsibility when using IaaS?

⚠ Common exam trap

CCSP often tests the misconception that the provider handles 'most' security in IaaS, when in fact the customer carries the majority of operational security responsibility for the guest stack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The customer is responsible for securing the operating system, applications, and data they deploy on the IaaS platform.

In IaaS, the provider secures the physical hosts, hypervisor, and network fabric, but the customer retains responsibility for the guest OS, middleware, applications, and data — including patching, hardening, and encryption choices. For a healthcare workload, that means the customer must secure the OS and application layer even though the provider owns the hardware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cloud provider is responsible for all security controls because they own the infrastructure.

    Why it's wrong here

    In IaaS the provider secures the physical hosts, network fabric and hypervisor, while the customer retains responsibility for guest OS patching, application security and data classification. It is tempting because the provider does own the hardware, and would be correct only for SaaS, where the provider operates the full stack.

  • ✗

    The customer has no responsibility for network security because the provider manages the hypervisor.

    Why it's wrong here

    The hypervisor sits with the provider, but the customer still configures security groups, subnets, firewalls and encryption of traffic within its own virtual network. It is tempting because hypervisor management is genuinely provider-side, and would be correct if the question asked which layer the provider alone controls.

  • ✗

    The cloud provider automatically encrypts all data at rest and in transit by default.

    Why it's wrong here

    Default encryption at rest is common, yet in-transit protection, key custody and application-layer controls remain customer duties under IaaS. It is tempting because provider consoles do show encryption toggles, and would be correct if the question asked about a managed database or SaaS offering.

  • ✓

    The customer is responsible for securing the operating system, applications, and data they deploy on the IaaS platform.

    Why this is correct

    Under the IaaS shared responsibility model the provider secures the physical hosts, hypervisor and facility, while the customer secures everything above: guest operating systems, middleware, applications and patient data. For healthcare records, that customer-side obligation is the most critical consideration.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.