nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #6

In a shared security responsibility model for IaaS, which two layers of the stack does the customer share responsibility for? (Choose two.)

The correct answer is B. Network Security D. Access Policies. In the IaaS shared responsibility model, the cloud provider owns the physical hardware, data center facilities, and the underlying infrastructure, while the customer takes on responsibility for the layers they control and configure. Network Security (B) is shared: the provider…

Submitted by yousef_jo· Apr 18, 2026Configuring access within a cloud solution environment

Question

In a shared security responsibility model for IaaS, which two layers of the stack does the customer share responsibility for? (Choose two.)

Options

  • AHardware
  • BNetwork Security
  • CStorage Encryption
  • DAccess Policies
  • EBoot

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    88% (22)
  • E
    8% (2)

Explanation

In the IaaS shared responsibility model, the cloud provider owns the physical hardware, data center facilities, and the underlying infrastructure, while the customer takes on responsibility for the layers they control and configure. Network Security (B) is shared: the provider secures the physical network infrastructure, but the customer is responsible for configuring virtual firewalls, security groups, and network policies. Access Policies (D) are also shared: the provider supplies the identity infrastructure, but the customer must configure and manage IAM roles, permissions, and user access. Hardware (A) is solely the provider's responsibility. Storage Encryption (C) and Boot (E) are primarily customer-configurable layers, but the question identifies B and D as the shared layers.

Topics

#Shared Responsibility Model#IaaS Security#Network Security#Access Control

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice