Courseiva

SSCP Systems and Application Security Practice Question

An organization is migrating a legacy application to a PaaS cloud environment. According to the shared responsibility model, which security control is the organization still responsible for?

⚠ Common exam trap

The trap is overestimating provider responsibility in PaaS — candidates assume the provider handles everything below the application, but the customer still owns application code security, IAM, and data protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Securing the application code against SQL injection

In the shared responsibility model for PaaS, the cloud provider manages the underlying infrastructure (network, OS, hypervisor, runtime), while the customer is responsible for the security of their application code and data. Securing application code against SQL injection is therefore the customer's responsibility. The other options are provider-managed in PaaS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configuring the network firewall at the cloud perimeter

    Why it's wrong here

    The cloud provider operates the perimeter network firewall in PaaS, so the customer does not configure it. It is tempting because on-premises environments require the organisation to manage its own edge firewall, and some PaaS offerings expose limited firewall or security-group settings that appear customer-controlled.

  • ✓

    Securing the application code against SQL injection

    Why this is correct

    In PaaS, the provider secures the platform, runtime and OS, but the customer retains responsibility for their application code. Input validation and parameterised queries preventing SQL injection remain the organisation's duty, satisfying the shared responsibility boundary for application-layer controls.

  • ✗

    Patching the underlying operating system

    Why it's wrong here

    Patching the underlying operating system is the provider's duty in PaaS, since the customer only manages the deployed application and its data. It is tempting because OS patching is a core customer task in IaaS and on-premises, so test-takers carry that habit across without adjusting for the higher abstraction.

  • ✗

    Managing the hypervisor and virtualization layer

    Why it's wrong here

    In PaaS the provider manages the hypervisor and virtualisation layer, so the customer cannot control it. It is tempting because on-premises or IaaS deployments leave virtualisation with the organisation, making this a genuine customer responsibility in those models rather than under PaaS.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.