Courseiva

SSCP Systems and Application Security Practice Question

A company is migrating to a PaaS cloud environment. According to the shared responsibility model, which THREE security responsibilities remain with the customer? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User access and identity management

In PaaS, the customer manages access policies, application-level security, and data protection, while the provider manages the runtime, OS, and infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch management of the underlying OS

    Why it's wrong here

    Under PaaS the provider patches the underlying operating system, so this responsibility does not remain with the customer. It tempts because IaaS leaves OS patching to the tenant; the correct customer duties concern application code, identity and data rather than the provider-managed runtime platform.

  • ✓

    User access and identity management

    Why this is correct

    In PaaS, the provider secures the platform and runtime, but the customer still controls who accesses the service. Managing user accounts, authentication and authorisation remains the customer's duty, satisfying the stem's shared responsibility constraint for identity.

  • ✓

    Data classification and encryption

    Why this is correct

    Data classification and encryption stay with the customer under every cloud service model, including PaaS. The provider secures the platform and infrastructure, but the customer alone determines sensitivity labels and holds the keys, satisfying the stem's requirement that these three responsibilities remain customer-owned.

  • ✓

    Security of the application code

    Why this is correct

    PaaS supplies the runtime and middleware, yet whatever code the customer deploys on it stays the customer's responsibility to secure. Patching application vulnerabilities and secure coding remain with the tenant, satisfying the stem's shared responsibility constraint.

  • ✗

    Physical security of the data center

    Why it's wrong here

    In PaaS the provider owns the data centre, so physical security sits with them, not the customer. It tempts because on-premises deployments place that duty squarely on the organisation; the customer's remaining responsibilities instead cover their own data, accounts and application-level configuration.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.