Courseiva

SSCP Systems and Application Security Practice Question

A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

⚠ Common exam trap

SSCP often tests where the responsibility boundary sits in IaaS — candidates over-attribute security tasks to the provider, forgetting that the customer owns the guest OS and everything above it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patching the guest operating system and web server software

Patching the guest operating system and web server software is correct because in the IaaS shared responsibility model, the customer controls and is responsible for everything from the guest OS upward — including OS patches, middleware, runtime, and application code. The provider secures the physical hosts, hypervisor, and network fabric beneath the virtualization layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network infrastructure security such as DDoS protection at the provider edge

    Why it's wrong here

    Edge DDoS protection forms part of the provider's network infrastructure on IaaS, not the customer's remit. It tempts because DDoS mitigation is a genuine customer duty when running dedicated internet circuits into an on-premises data centre that the organisation controls end to end.

  • ✗

    Hypervisor security and vulnerability management

    Why it's wrong here

    Hypervisor hardening sits with the provider on IaaS, since it virtualises the customer's instances; the customer secures only the guest OS and above. It tempts because hypervisor patching is a genuine customer duty under on-premises virtualisation, where the organisation owns the entire stack.

  • ✓

    Patching the guest operating system and web server software

    Why this is correct

    In IaaS, the provider secures the physical hosts, network and hypervisor only. The customer retains control of everything above the hypervisor, so patching the guest OS and web server software falls to them. This satisfies the shared responsibility split for IaaS workloads.

  • ✗

    Physical security of the data center hosting the servers

    Why it's wrong here

    Physical security of the data centre remains the provider's responsibility on IaaS, as the customer never accesses the facility. It tempts because physical controls are a real customer obligation in on-premises or colocation hosting, where the organisation owns or leases the building.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.