CCSP Cloud Concepts, Architecture, and Design Practice Question
An organization is using a public cloud IaaS and wants to ensure they understand which security responsibilities fall on them. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security of the guest operating system
In IaaS, the customer is responsible for securing the operating system, applications, and data, while the provider secures the physical infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hypervisor security
Why it's wrong here
Hypervisor is managed by the cloud provider.
- ✗
Physical security of data centers
Why it's wrong here
Physical security is the provider's responsibility.
- ✓
Security of the guest operating system
Why this is correct
Correct. The customer manages the OS, apps, and data.
- ✗
Network infrastructure hardening
Why it's wrong here
The provider handles the underlying network infrastructure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.