Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?

⚠ Common exam trap

The trap here is assuming that because the provider runs the application, the consumer has no security duties left, when identity and data governance always stay with the subscriber.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managing user identities, access rights, and data classification

In SaaS the provider secures everything from the physical facility up through the application, while the consumer retains control over its own identities, access entitlements, and the data it chooses to place in the service. Physical security, hypervisor maintenance, and guest operating system patching all sit beneath the application and never move to the subscriber.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Applying hypervisor patches to the multi-tenant virtualization layer

    Why it's wrong here

    The virtualization layer that separates tenants is operated and patched exclusively by the provider, and subscribers have no administrative access to it. Allowing a subscriber to patch a hypervisor would break tenant isolation for every other customer. This responsibility therefore never transfers to the consumer in a SaaS arrangement, regardless of the data sensitivity involved.

  • ✗

    Patching the guest operating system on the provider's hosts

    Why it's wrong here

    In a SaaS model the provider owns and patches the entire stack beneath the application, including the hypervisor and guest operating systems. Subscribers have no visibility into or control over those hosts, so they cannot patch them even if they wanted to. Assigning this task to the consumer misreads the shared responsibility boundary and would duplicate work the provider already performs.

  • ✓

    Managing user identities, access rights, and data classification

    Why this is correct

    Even when the provider operates the application stack, the subscriber remains accountable for who may access the service and what data is placed in it. Identity lifecycle management, entitlement review, multi-factor authentication enforcement, and classifying the data being uploaded are classic consumer responsibilities. These controls govern the subscriber's own users and information rather than the provider's infrastructure, so they stay with the consumer.

  • ✗

    Maintaining the physical security of the provider's data centers

    Why it's wrong here

    Physical safeguards such as fencing, badge access, surveillance, and environmental controls are always the provider's responsibility in a public SaaS offering. Subscribers typically cannot enter the facility and have no operational role in its protection. This option confuses the infrastructure layer, which the provider owns, with the governance layer that remains with the consumer under the shared responsibility model.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.