CAS-004 Security Architecture Practice Question
An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?
⚠ Common exam trap
CAS-005 often tests the shared responsibility model by asking which model places the MOST responsibility on the customer — candidates incorrectly pick SaaS or PaaS because they confuse 'cloud-first' with 'provider-managed.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IaaS
IaaS (Infrastructure as a Service) places the most security responsibility on the customer because the provider only manages the physical hardware, hypervisor, and network fabric. The customer is responsible for the guest OS, middleware, runtime, applications, and data — including patching, hardening, IAM, and encryption. Under SOC 2, this means the customer must implement and evidence most of the Trust Services Criteria controls themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IaaS
Why this is correct
IaaS leaves the customer responsible for the guest OS, runtime, middleware, applications and data, whereas PaaS and SaaS shift those layers to the provider. This maximal customer ownership of the stack is precisely what satisfies the stem's requirement for the model placing the most security responsibility on the customer.
- ✗
FaaS
Why it's wrong here
FaaS shifts patching of the runtime and OS to the provider, leaving only function code and identity to the customer, so it carries less customer responsibility than IaaS. Tempting because serverless feels hands-off, but the question asks which model places the most responsibility on the customer.
- ✗
SaaS
Why it's wrong here
SaaS places the least security responsibility on the customer, since the provider manages the application, data platform and infrastructure. Tempting because compliance obligations still fall on the customer organisation, but operational security controls sit with the vendor, not the tenant.
- ✗
PaaS
Why it's wrong here
PaaS leaves patching of the runtime, middleware and OS to the provider, so customer responsibility covers only applications and data. Tempting because developers still configure and secure their deployed code, but IaaS demands far more, including guest OS hardening and network controls.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.