nerdexam
Palo_Alto_Networks

PCCET · Question #25

Which aspect of a SaaS application requires compliance with local organizational security policies?

The correct answer is C. Acceptable use of the SaaS application. In a SaaS model, the cloud provider owns and manages the physical infrastructure, encryption at rest, and vulnerability management. The customer organization retains responsibility for governing how its users interact with the application - this is acceptable use policy. Items…

Submitted by stefanr· Apr 18, 2026Cloud Security

Question

Which aspect of a SaaS application requires compliance with local organizational security policies?

Options

  • ATypes of physical storage media used
  • BData-at-rest encryption standards
  • CAcceptable use of the SaaS application
  • DVulnerability scanning and management

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    85% (23)
  • D
    4% (1)

Explanation

In a SaaS model, the cloud provider owns and manages the physical infrastructure, encryption at rest, and vulnerability management. The customer organization retains responsibility for governing how its users interact with the application - this is acceptable use policy. Items A, B, and D all fall under the provider's shared responsibility scope, not the customer's.

Topics

#SaaS security#Organizational policies#Acceptable Use Policy (AUP)#Cloud shared responsibility

Community Discussion

No community discussion yet for this question.

Full PCCET Practice