mediumMultiple Choice
CCSP Practice Question: Refer to the exhibit
Exhibit
[2023-10-05 14:23:11] ALERT: Unauthorized access attempt detected from IP 203.0.113.50 to customer data bucket. Access denied due to IAM policy restriction. Incident ID: INC-78901.
Refer to the exhibit. A security analyst sees this alert. According to the shared responsibility model, who is primarily responsible for ensuring that the IAM policy correctly restricts access?
⚠ Common exam trap
CCSP often tests whether candidates incorrectly assume the cloud provider shares responsibility for customer-defined IAM policies, when in fact IAM configuration is exclusively a customer responsibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer
Under the cloud shared responsibility model, the customer is always responsible for the security 'in' the cloud — including identity and access management (IAM) policies, user permissions, and access controls. The cloud provider secures the infrastructure 'of' the cloud, but configuring IAM policies to correctly restrict access is squarely a customer responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The third-party auditor
Why it's wrong here
A third-party auditor provides independent assurance and reports findings; it does not own or configure the customer's IAM policies. Auditors are tempting because they review access controls, but under the shared responsibility model the cloud customer remains accountable for correctly scoping its own IAM permissions.
- ✓
The customer
Why this is correct
Under the shared responsibility model, the cloud provider secures the infrastructure, while the customer owns identity and access management configuration. The customer defines and maintains IAM policies, so ensuring a policy correctly restricts access remains the customer's responsibility, not the provider's.
- ✗
Both equally
Why it's wrong here
Responsibility for policy content lies with the customer.
- ✗
The cloud provider
Why it's wrong here
The provider secures the cloud itself — hardware, hypervisor, managed service availability — but IAM policy content authored by the customer defines who may call which API actions on which resources. Providers supply policy engines and defaults, never the customer's access decisions. Tempting because providers do patch and operate the underlying infrastructure, yet that layer excludes tenant identity authorisation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.