Courseiva
mediumMultiple Choice

CCSP Practice Question: Refer to the exhibit

Exhibit

[2023-10-05 14:23:11] ALERT: Unauthorized access attempt detected from IP 203.0.113.50 to customer data bucket. Access denied due to IAM policy restriction. Incident ID: INC-78901.

Refer to the exhibit. A security analyst sees this alert. According to the shared responsibility model, who is primarily responsible for ensuring that the IAM policy correctly restricts access?

⚠ Common exam trap

CCSP often tests whether candidates incorrectly assume the cloud provider shares responsibility for customer-defined IAM policies, when in fact IAM configuration is exclusively a customer responsibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The customer

Under the cloud shared responsibility model, the customer is always responsible for the security 'in' the cloud — including identity and access management (IAM) policies, user permissions, and access controls. The cloud provider secures the infrastructure 'of' the cloud, but configuring IAM policies to correctly restrict access is squarely a customer responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The third-party auditor

    Why it's wrong here

    A third-party auditor provides independent assurance and reports findings; it does not own or configure the customer's IAM policies. Auditors are tempting because they review access controls, but under the shared responsibility model the cloud customer remains accountable for correctly scoping its own IAM permissions.

  • ✓

    The customer

    Why this is correct

    Under the shared responsibility model, the cloud provider secures the infrastructure, while the customer owns identity and access management configuration. The customer defines and maintains IAM policies, so ensuring a policy correctly restricts access remains the customer's responsibility, not the provider's.

  • ✗

    Both equally

    Why it's wrong here

    Responsibility for policy content lies with the customer.

  • ✗

    The cloud provider

    Why it's wrong here

    The provider secures the cloud itself — hardware, hypervisor, managed service availability — but IAM policy content authored by the customer defines who may call which API actions on which resources. Providers supply policy engines and defaults, never the customer's access decisions. Tempting because providers do patch and operate the underlying infrastructure, yet that layer excludes tenant identity authorisation.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.