CCSP Cloud Concepts, Architecture, and Design Practice Question
An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?
⚠ Common exam trap
The trap here is assuming that because the provider runs the application, the consumer has no security duties left, when identity and data governance always stay with the subscriber.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user identities, access rights, and data classification
In SaaS the provider secures everything from the physical facility up through the application, while the consumer retains control over its own identities, access entitlements, and the data it chooses to place in the service. Physical security, hypervisor maintenance, and guest operating system patching all sit beneath the application and never move to the subscriber.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Applying hypervisor patches to the multi-tenant virtualization layer
Why it's wrong here
The virtualization layer that separates tenants is operated and patched exclusively by the provider, and subscribers have no administrative access to it. Allowing a subscriber to patch a hypervisor would break tenant isolation for every other customer. This responsibility therefore never transfers to the consumer in a SaaS arrangement, regardless of the data sensitivity involved.
- ✗
Patching the guest operating system on the provider's hosts
Why it's wrong here
In a SaaS model the provider owns and patches the entire stack beneath the application, including the hypervisor and guest operating systems. Subscribers have no visibility into or control over those hosts, so they cannot patch them even if they wanted to. Assigning this task to the consumer misreads the shared responsibility boundary and would duplicate work the provider already performs.
- ✓
Managing user identities, access rights, and data classification
Why this is correct
Even when the provider operates the application stack, the subscriber remains accountable for who may access the service and what data is placed in it. Identity lifecycle management, entitlement review, multi-factor authentication enforcement, and classifying the data being uploaded are classic consumer responsibilities. These controls govern the subscriber's own users and information rather than the provider's infrastructure, so they stay with the consumer.
- ✗
Maintaining the physical security of the provider's data centers
Why it's wrong here
Physical safeguards such as fencing, badge access, surveillance, and environmental controls are always the provider's responsibility in a public SaaS offering. Subscribers typically cannot enter the facility and have no operational role in its protection. This option confuses the infrastructure layer, which the provider owns, with the governance layer that remains with the consumer under the shared responsibility model.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.