Courseiva

SSCP Systems and Application Security Practice Question

A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

⚠ Common exam trap

The trap is mixing up responsibilities: candidates often think the provider patches the guest OS in IaaS, but the exam tests that the customer owns guest OS patching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patching the guest operating system

In the IaaS shared responsibility model, the customer is responsible for securing the guest operating system, including patching, because the cloud provider manages the hypervisor and physical infrastructure. The customer controls the OS and applications running on the IaaS instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patching the hypervisor

    Why it's wrong here

    Hypervisor patching belongs to the provider in IaaS, as they manage the virtualisation layer beneath the guest. It is tempting because customers patch their own guest operating systems and applications, so patching appears to be a shared duty; however, the hypervisor itself is provider-controlled infrastructure.

  • ✗

    Physical security of data centers

    Why it's wrong here

    Physical security of data centres sits with the cloud provider under IaaS, since they own and operate the facilities, hardware and environmental controls. It is tempting because physical controls remain a customer concern in on-premises deployments, where the organisation owns the building and is accountable for perimeter, access and surveillance.

  • ✗

    Securing the network infrastructure

    Why it's wrong here

    In IaaS, the customer secures the operating systems, applications and data, while the provider secures the physical hosts, storage and network fabric. It tempts because customers configure virtual networks and firewalls, but the underlying network infrastructure remains the provider's responsibility.

  • ✓

    Patching the guest operating system

    Why this is correct

    Patching the guest operating system falls to the customer under IaaS, since the provider manages only the hypervisor, physical hosts and network fabric. The customer retains control of everything from the guest OS upward, satisfying the stem's shared responsibility constraint.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.