In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?
Data classification and encryption remain customer responsibilities because the provider cannot determine sensitivity or manage keys without the tenant's context. In the shared responsibility model, the customer always owns data governance, including classifying information and controlling encryption keys, while Microsoft Entra ID and the underlying infrastructure stay with the provider.
Why this answer
In the shared responsibility model for cloud security, the customer is always responsible for the security of their data, including classification and encryption. This includes determining data sensitivity, applying appropriate encryption at rest and in transit, and managing encryption keys. The cloud provider is responsible for security of the cloud (physical, network, hypervisor), while the customer is responsible for security in the cloud.
Exam trap
CAS-005 often tests the shared responsibility model by presenting responsibilities that seem like they could be either party's. The trap is assuming the provider handles data encryption because they offer encryption tools, but the customer must still configure and manage it.
How to eliminate wrong answers
Option B is wrong because physical security of data centers is always the responsibility of the cloud provider, as customers have no access to or control over the physical infrastructure. Option C is wrong because network infrastructure security (e.g., routers, switches, physical network) is managed by the cloud provider under the shared responsibility model. Option D is wrong because hypervisor security is part of the virtualization layer managed by the cloud provider; customers do not have access to the hypervisor in public cloud environments.