CCSP Cloud Concepts, Architecture, and Design Practice Question
In the shared responsibility model for public cloud IaaS, which of the following is typically the responsibility of the cloud customer?
⚠ Common exam trap
The trap is assuming the provider handles all patching in the cloud; candidates must remember that in IaaS the line is drawn at the hypervisor, so guest OS patching belongs to the customer, while hypervisor and physical security belong to the provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing virtual machine guest OS patches
In the IaaS shared responsibility model, the cloud provider secures the physical facilities, network backbone, and hypervisor, while the customer is responsible for everything from the guest OS upward — including patching the guest operating system, middleware, and applications. Managing VM guest OS patches is therefore a customer responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network infrastructure redundancy
Why it's wrong here
The provider owns and maintains the physical network fabric, including redundancy, in IaaS; customers secure their own virtual networks, subnets, and firewall rules. It is tempting because customers configure network security groups and routing, but that is logical configuration, not the underlying infrastructure's redundancy.
- ✓
Managing virtual machine guest OS patches
Why this is correct
In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer controls everything from the guest OS upward. Patching the guest operating system is therefore the customer's task, since the provider has no access to or control over that layer.
- ✗
Physical security of data centers
Why it's wrong here
Physical security of data centres sits with the cloud provider under IaaS, since the provider owns and operates the facilities; customers cannot control cages, guards or biometrics. It is tempting because customers remain accountable for the data itself, but that accountability does not extend to the provider's buildings.
- ✗
Patching the hypervisor
Why it's wrong here
Hypervisor patching belongs to the cloud provider, which owns the virtualisation layer beneath the guest. Customers patch guest operating systems, middleware and applications only. It is tempting because customers do patch their own VMs, but the hypervisor sits outside their administrative boundary.
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.