CV0-003 · Question #3
A company wants to take advantage of cloud benefits while retaining control of and maintaining compliance with all its security policy obligations. Based on the non-functional requirements, which of…
The correct answer is B. IaaS, as the cloud provider has a minimal level of security responsibility. IaaS gives the customer maximum control over OS, applications, data, and security configurations, allowing full ownership of security policy compliance while still leveraging cloud infrastructure benefits.
Question
A company wants to take advantage of cloud benefits while retaining control of and maintaining compliance with all its security policy obligations. Based on the non-functional requirements, which of the following should the company use?
Options
- AHybrid cloud, as use is restricted to trusted customers
- BIaaS, as the cloud provider has a minimal level of security responsibility
- CPaaS, as the cloud customer has the most security responsibility
- DSaaS, as the cloud provider has less security responsibility
How the community answered
(49 responses)- A2% (1)
- B86% (42)
- C8% (4)
- D4% (2)
Why each option
IaaS gives the customer maximum control over OS, applications, data, and security configurations, allowing full ownership of security policy compliance while still leveraging cloud infrastructure benefits.
Hybrid cloud describes a deployment topology mixing private and public cloud, not a service model that inherently grants the customer control over security responsibilities.
In the IaaS shared responsibility model, the cloud provider is responsible only for physical hardware, networking, and the hypervisor layer - the minimal scope. The customer retains full responsibility and control over the operating system, middleware, applications, and all security configurations. This model allows the company to enforce its own security policies end-to-end while still benefiting from scalable cloud infrastructure.
In PaaS, the provider manages the runtime, middleware, and OS layer, so the customer has less security control than in IaaS, not more.
In SaaS, the provider manages nearly the entire stack including the application itself, leaving the customer with the least security control of any service model.
Concept tested: IaaS shared responsibility model and customer security control
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
Topics
Community Discussion
No community discussion yet for this question.