SSCP Systems and Application Security Practice Question
A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?
⚠ Common exam trap
The trap is mixing up responsibilities: candidates often think the provider patches the guest OS in IaaS, but the exam tests that the customer owns guest OS patching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patching the guest operating system
In the IaaS shared responsibility model, the customer is responsible for securing the guest operating system, including patching, because the cloud provider manages the hypervisor and physical infrastructure. The customer controls the OS and applications running on the IaaS instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patching the hypervisor
Why it's wrong here
Hypervisor patching belongs to the provider in IaaS, as they manage the virtualisation layer beneath the guest. It is tempting because customers patch their own guest operating systems and applications, so patching appears to be a shared duty; however, the hypervisor itself is provider-controlled infrastructure.
- ✗
Physical security of data centers
Why it's wrong here
Physical security of data centres sits with the cloud provider under IaaS, since they own and operate the facilities, hardware and environmental controls. It is tempting because physical controls remain a customer concern in on-premises deployments, where the organisation owns the building and is accountable for perimeter, access and surveillance.
- ✗
Securing the network infrastructure
Why it's wrong here
In IaaS, the customer secures the operating systems, applications and data, while the provider secures the physical hosts, storage and network fabric. It tempts because customers configure virtual networks and firewalls, but the underlying network infrastructure remains the provider's responsibility.
- ✓
Patching the guest operating system
Why this is correct
Patching the guest operating system falls to the customer under IaaS, since the provider manages only the hypervisor, physical hosts and network fabric. The customer retains control of everything from the guest OS upward, satisfying the stem's shared responsibility constraint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.