CAS-004 Security Architecture Practice Question
A security architect is evaluating a cloud service provider's ability to support a customer's compliance with PCI DSS. The customer will store cardholder data in the cloud. The architect needs to determine which party is responsible for configuring encryption of the data at rest and managing the encryption keys. According to the shared responsibility model, which of the following is the MOST accurate statement?
⚠ Common exam trap
The trap here is assuming that because the cloud provider owns the infrastructure, it also owns all data protection responsibilities, including encryption and key management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer is responsible for enabling encryption at rest and managing keys, but the provider may offer key management services.
In the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing keys. The cloud provider may offer key management services, but the customer must configure them to meet PCI DSS requirements. The other options either reverse responsibilities or incorrectly assign full responsibility to one party.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The customer is responsible for enabling encryption at rest and managing keys, but the provider may offer key management services.
Why this is correct
Under the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing encryption keys. The cloud provider may offer key management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS, but the customer must configure and use them appropriately to meet PCI DSS requirements.
- ✗
The customer is responsible for physical security of the data center, and the provider handles encryption.
Why it's wrong here
Physical security of the data center is the cloud provider's responsibility, not the customer's. The customer is responsible for encryption of its data at rest and key management. This option reverses the responsibilities, which would lead to compliance gaps and potential data exposure.
- ✗
PCI DSS compliance is solely the cloud provider's responsibility because they own the infrastructure.
Why it's wrong here
PCI DSS compliance is a shared responsibility. The cloud provider is responsible for the compliance of its infrastructure, but the customer is responsible for how cardholder data is stored, processed, and transmitted within the cloud environment. The customer must ensure that its configurations and applications meet PCI DSS requirements.
- ✗
The cloud provider is always responsible for encrypting cardholder data at rest and managing keys.
Why it's wrong here
In the shared responsibility model, the cloud provider is responsible for security OF the cloud, such as physical security and infrastructure, but encryption of customer data at rest is typically a customer responsibility when using infrastructure as a service or platform as a service. The provider may offer encryption capabilities, but the customer must enable and manage them.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.