nerdexam
CompTIA

CV0-003 · Question #3

A company wants to take advantage of cloud benefits while retaining control of and maintaining compliance with all its security policy obligations. Based on the non-functional requirements, which of…

The correct answer is B. IaaS, as the cloud provider has a minimal level of security responsibility. IaaS gives the customer maximum control over OS, applications, data, and security configurations, allowing full ownership of security policy compliance while still leveraging cloud infrastructure benefits.

Cloud Architecture and Design

Question

A company wants to take advantage of cloud benefits while retaining control of and maintaining compliance with all its security policy obligations. Based on the non-functional requirements, which of the following should the company use?

Options

  • AHybrid cloud, as use is restricted to trusted customers
  • BIaaS, as the cloud provider has a minimal level of security responsibility
  • CPaaS, as the cloud customer has the most security responsibility
  • DSaaS, as the cloud provider has less security responsibility

How the community answered

(49 responses)
  • A
    2% (1)
  • B
    86% (42)
  • C
    8% (4)
  • D
    4% (2)

Why each option

IaaS gives the customer maximum control over OS, applications, data, and security configurations, allowing full ownership of security policy compliance while still leveraging cloud infrastructure benefits.

AHybrid cloud, as use is restricted to trusted customers

Hybrid cloud describes a deployment topology mixing private and public cloud, not a service model that inherently grants the customer control over security responsibilities.

BIaaS, as the cloud provider has a minimal level of security responsibilityCorrect

In the IaaS shared responsibility model, the cloud provider is responsible only for physical hardware, networking, and the hypervisor layer - the minimal scope. The customer retains full responsibility and control over the operating system, middleware, applications, and all security configurations. This model allows the company to enforce its own security policies end-to-end while still benefiting from scalable cloud infrastructure.

CPaaS, as the cloud customer has the most security responsibility

In PaaS, the provider manages the runtime, middleware, and OS layer, so the customer has less security control than in IaaS, not more.

DSaaS, as the cloud provider has less security responsibility

In SaaS, the provider manages nearly the entire stack including the application itself, leaving the customer with the least security control of any service model.

Concept tested: IaaS shared responsibility model and customer security control

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility

Topics

#IaaS#shared responsibility model#compliance#cloud service models

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice