Courseiva

SSCP Systems and Application Security Practice Question

A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managing application security (e.g., patching web app code)

In IaaS, customer manages OS, applications, and network traffic controls (guest OS firewall).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Managing application security (e.g., patching web app code)

    Why this is correct

    Under IaaS the provider manages the platform beneath the VM, leaving everything above the operating system to the tenant. Application security, including patching web app code, therefore falls to the customer, satisfying the stem's customer-responsibility constraint rather than the provider's managed scope.

  • ✓

    Configuring the host-based firewall on VMs

    Why this is correct

    In IaaS the provider secures the hypervisor and physical hosts, but the guest VM's host-based firewall is configured by the customer. This satisfies the stem's customer-responsibility constraint because network filtering at the operating-system level remains under tenant control, not the provider's.

  • ✓

    Patching the guest operating system

    Why this is correct

    IaaS delivers raw virtual machines, so the provider patches the hypervisor and underlying infrastructure only. The guest operating system, including its kernel and libraries, is the customer's to patch. This directly satisfies the stem's requirement for customer responsibilities under the shared responsibility model.

  • ✗

    Physical security of the data center

    Why it's wrong here

    Physical data centre security stays with the cloud provider under IaaS, since the customer never accesses hardware. It tempts because customers secure their own on-premises facilities, but in IaaS the provider owns the building, racks, and perimeter, leaving the customer responsible for guest OS, applications, and data.

  • ✗

    Securing the hypervisor

    Why it's wrong here

    The hypervisor is provider-managed in IaaS, sitting beneath the customer's guest operating system. It tempts because customers harden virtualisation hosts on-premises, but in IaaS the provider controls the hypervisor layer, while the customer secures the guest OS, middleware, applications, and data.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?

easy
  • A.Network infrastructure security
  • B.Hypervisor security and patching
  • ✓ C.Operating system security and patch management
  • D.Physical security of the data center

Why C: In IaaS, the customer is responsible for securing the operating system, including patch management, because the provider only manages the hypervisor and physical infrastructure. Operating system security and patching is therefore a customer responsibility. The other options are provider responsibilities in IaaS.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.