nerdexam
Cisco

350-701 · Question #637

In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?

The correct answer is C. PaaS. In the Platform as a Service (PaaS) model, the customer is responsible for the applications they deploy, including their security and vulnerability management, while the provider manages the underlying infrastructure and platform.

Submitted by layla.eg· Mar 30, 2026

Question

In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?

Options

  • AVMaaS
  • BIaaS
  • CPaaS
  • DSaaS

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    84% (31)
  • D
    3% (1)

Why each option

In the Platform as a Service (PaaS) model, the customer is responsible for the applications they deploy, including their security and vulnerability management, while the provider manages the underlying infrastructure and platform.

AVMaaS

VMaaS (Vulnerability Management as a Service) is a specific security service, not a general cloud service model like IaaS, PaaS, or SaaS, and it typically involves outsourcing vulnerability management, not defining responsibility in the cloud shared responsibility model.

BIaaS

In IaaS (Infrastructure as a Service), the customer has more responsibility, including the operating system, middleware, and applications, and would be responsible for application vulnerabilities as well as OS vulnerabilities. However, PaaS specifically highlights application layer responsibility while abstracting more of the underlying stack.

CPaaSCorrect

In a PaaS (Platform as a Service) model, the cloud provider manages the operating system, virtualization, servers, storage, and networking, as well as the runtime environment. However, the customer is responsible for the applications deployed on that platform, including writing, deploying, and managing their code, and therefore, scanning for and mitigating any application-specific vulnerabilities within their deployed applications.

DSaaS

In SaaS (Software as a Service), the provider manages almost the entire stack, including the application, meaning the provider is primarily responsible for application vulnerability management, though customers are responsible for their data and usage.

Concept tested: Cloud shared responsibility model (PaaS)

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility

Topics

#Cloud Service Models#Shared Responsibility Model#Application Security#PaaS

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice