nerdexam
CompTIA

CAS-003 · Question #415

An organization is in the process of evaluating service providers for an upcoming migration to cloud-based services for the organization's ERP system. As part of the requirements defined by the…

The correct answer is B. Private cloud services with single-tenancy PaaS services. A private cloud with single-tenancy PaaS provides dedicated, isolated infrastructure for one organization, directly satisfying regulatory requirements for data segmentation and isolation.

Enterprise Security Architecture

Question

An organization is in the process of evaluating service providers for an upcoming migration to cloud-based services for the organization's ERP system. As part of the requirements defined by the project team, regulatory requirements specify segmentation and isolation of the organization's data. Which of the following should the vendor management team identify as a requirement during the procurement process?

Options

  • APublic cloud services with single-tenancy IaaS architectures
  • BPrivate cloud services with single-tenancy PaaS services
  • CPrivate cloud services with multitenancy in place for private SaaS environments
  • DPublic cloud services with private SaaS environments supported by private IaaS backbones

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    79% (26)
  • C
    12% (4)
  • D
    3% (1)

Why each option

A private cloud with single-tenancy PaaS provides dedicated, isolated infrastructure for one organization, directly satisfying regulatory requirements for data segmentation and isolation.

APublic cloud services with single-tenancy IaaS architectures

Public cloud IaaS with single-tenancy provides dedicated hardware but still operates within shared public cloud infrastructure, which may not satisfy stringent regulatory segmentation requirements.

BPrivate cloud services with single-tenancy PaaS servicesCorrect

A private cloud environment restricts infrastructure access to a single organization, eliminating cross-customer data exposure. Single-tenancy in PaaS ensures dedicated compute and storage resources are not shared with other customers, meeting strict regulatory mandates for data segmentation and isolation. Together, these properties give the organization full control over data boundaries and auditability required for ERP compliance.

CPrivate cloud services with multitenancy in place for private SaaS environments

Multitenancy in a private SaaS environment means multiple customers share the same application instance, violating the isolation requirement even if the underlying cloud is private.

DPublic cloud services with private SaaS environments supported by private IaaS backbones

Public cloud with private SaaS backed by private IaaS is a hybrid model that retains reliance on public cloud infrastructure, introducing compliance gaps for organizations requiring strict data isolation.

Concept tested: Cloud tenancy models and regulatory data isolation requirements

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf

Topics

#cloud services#vendor procurement#data isolation#PaaS tenancy

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice