SSCP Systems and Application Security Practice Question
A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing application security (e.g., patching web app code)
In IaaS, customer manages OS, applications, and network traffic controls (guest OS firewall).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Managing application security (e.g., patching web app code)
Why this is correct
Under IaaS the provider manages the platform beneath the VM, leaving everything above the operating system to the tenant. Application security, including patching web app code, therefore falls to the customer, satisfying the stem's customer-responsibility constraint rather than the provider's managed scope.
- ✓
Configuring the host-based firewall on VMs
Why this is correct
In IaaS the provider secures the hypervisor and physical hosts, but the guest VM's host-based firewall is configured by the customer. This satisfies the stem's customer-responsibility constraint because network filtering at the operating-system level remains under tenant control, not the provider's.
- ✓
Patching the guest operating system
Why this is correct
IaaS delivers raw virtual machines, so the provider patches the hypervisor and underlying infrastructure only. The guest operating system, including its kernel and libraries, is the customer's to patch. This directly satisfies the stem's requirement for customer responsibilities under the shared responsibility model.
- ✗
Physical security of the data center
Why it's wrong here
Physical data centre security stays with the cloud provider under IaaS, since the customer never accesses hardware. It tempts because customers secure their own on-premises facilities, but in IaaS the provider owns the building, racks, and perimeter, leaving the customer responsible for guest OS, applications, and data.
- ✗
Securing the hypervisor
Why it's wrong here
The hypervisor is provider-managed in IaaS, sitting beneath the customer's guest operating system. It tempts because customers harden virtualisation hosts on-premises, but in IaaS the provider controls the hypervisor layer, while the customer secures the guest OS, middleware, applications, and data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?
easy- A.Network infrastructure security
- B.Hypervisor security and patching
- ✓ C.Operating system security and patch management
- D.Physical security of the data center
Why C: In IaaS, the customer is responsible for securing the operating system, including patch management, because the provider only manages the hypervisor and physical infrastructure. Operating system security and patching is therefore a customer responsibility. The other options are provider responsibilities in IaaS.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.