nerdexam
CompTIA

CAS-005 · Question #316

Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?

The correct answer is A. Level of control and influence governments have over cloud service providers. When adopting serverless computing, organizations must consider the geopolitical risk stemming from the control and influence governments might exert over their chosen cloud service providers, which can impact data sovereignty and compliance.

Submitted by hassan_iq· Mar 6, 2026Governance, Risk, and Compliance

Question

Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?

Options

  • ALevel of control and influence governments have over cloud service providers
  • BType of virtualization or emulation technology used in the provisioning of services
  • CVertical scalability of the infrastructure underpinning the serverless offerings
  • DUse of third-party monitoring of service provisioning and configurations

How the community answered

(16 responses)
  • A
    69% (11)
  • B
    19% (3)
  • C
    6% (1)
  • D
    6% (1)

Why each option

When adopting serverless computing, organizations must consider the geopolitical risk stemming from the control and influence governments might exert over their chosen cloud service providers, which can impact data sovereignty and compliance.

ALevel of control and influence governments have over cloud service providersCorrect

The level of control and influence governments have over cloud service providers (CSPs) is a significant security risk for serverless computing, as it can affect data residency, compliance with various national laws, and the potential for government access to data, which is a concern for organizations with sensitive data or operations in multiple jurisdictions.

BType of virtualization or emulation technology used in the provisioning of services

The specific virtualization or emulation technology used by the CSP is generally an implementation detail managed by the provider and less of a direct security risk for the organization consuming serverless services, which focuses on the abstraction layer.

CVertical scalability of the infrastructure underpinning the serverless offerings

Vertical scalability is a characteristic of the underlying infrastructure that supports serverless, which is managed by the CSP and is more related to performance and cost than a direct security risk for the organization.

DUse of third-party monitoring of service provisioning and configurations

The use of third-party monitoring can be a security benefit if it enhances visibility, or a risk if the third party is untrusted; however, it's not a fundamental risk inherent to the adoption of serverless computing itself like government influence.

Concept tested: Serverless computing security risks, geopolitical risk, data sovereignty

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/data-residency-overview?view=o365-worldwide

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice