mediumMultiple SelectObjective-mapped
CCSP Practice Question: Which TWO responsibilities are typically shared…
Which TWO responsibilities are typically shared between the cloud customer and the cloud provider in an IaaS model? (Choose two.)
⚠ Common exam trap
ISC2 often tests the misconception that hypervisor security is a shared responsibility, but in IaaS, the provider alone secures the hypervisor, while the customer is responsible for guest OS and application-level security controls like security groups and virtual firewalls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management of security group rules.
In an IaaS model, the cloud customer is responsible for managing security group rules, which act as virtual stateful firewalls controlling inbound and outbound traffic at the instance level. The cloud provider is responsible for the underlying network infrastructure, but the customer must configure these rules to enforce least-privilege access. This shared responsibility is explicitly defined in the AWS Shared Responsibility Model and similar frameworks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical security of data centers.
Why it's wrong here
Physical security is always the provider's responsibility.
- ✗
Hypervisor security.
Why it's wrong here
Hypervisor security is the provider's responsibility.
- ✓
Management of security group rules.
Why this is correct
Both customer (defines rules) and provider (enforces them) share this.
- ✗
Patching the guest operating system.
Why it's wrong here
Patching the OS is the customer's sole responsibility.
- ✓
Configuration of virtual network firewalls.
Why this is correct
The customer configures firewall rules, but the provider ensures the underlying infrastructure functions correctly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.