PCCET · Question #25
Which aspect of a SaaS application requires compliance with local organizational security policies?
The correct answer is C. Acceptable use of the SaaS application. In a SaaS model, the cloud provider owns and manages the physical infrastructure, encryption at rest, and vulnerability management. The customer organization retains responsibility for governing how its users interact with the application - this is acceptable use policy. Items…
Question
Which aspect of a SaaS application requires compliance with local organizational security policies?
Options
- ATypes of physical storage media used
- BData-at-rest encryption standards
- CAcceptable use of the SaaS application
- DVulnerability scanning and management
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C85% (23)
- D4% (1)
Explanation
In a SaaS model, the cloud provider owns and manages the physical infrastructure, encryption at rest, and vulnerability management. The customer organization retains responsibility for governing how its users interact with the application - this is acceptable use policy. Items A, B, and D all fall under the provider's shared responsibility scope, not the customer's.
Topics
Community Discussion
No community discussion yet for this question.