Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?

⚠ Common exam trap

CAS-005 often tests the shared responsibility model by asking which model places the MOST responsibility on the customer — candidates incorrectly pick SaaS or PaaS because they confuse 'cloud-first' with 'provider-managed.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IaaS

IaaS (Infrastructure as a Service) places the most security responsibility on the customer because the provider only manages the physical hardware, hypervisor, and network fabric. The customer is responsible for the guest OS, middleware, runtime, applications, and data — including patching, hardening, IAM, and encryption. Under SOC 2, this means the customer must implement and evidence most of the Trust Services Criteria controls themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IaaS

    Why this is correct

    IaaS leaves the customer responsible for the guest OS, runtime, middleware, applications and data, whereas PaaS and SaaS shift those layers to the provider. This maximal customer ownership of the stack is precisely what satisfies the stem's requirement for the model placing the most security responsibility on the customer.

  • ✗

    FaaS

    Why it's wrong here

    FaaS shifts patching of the runtime and OS to the provider, leaving only function code and identity to the customer, so it carries less customer responsibility than IaaS. Tempting because serverless feels hands-off, but the question asks which model places the most responsibility on the customer.

  • ✗

    SaaS

    Why it's wrong here

    SaaS places the least security responsibility on the customer, since the provider manages the application, data platform and infrastructure. Tempting because compliance obligations still fall on the customer organisation, but operational security controls sit with the vendor, not the tenant.

  • ✗

    PaaS

    Why it's wrong here

    PaaS leaves patching of the runtime, middleware and OS to the provider, so customer responsibility covers only applications and data. Tempting because developers still configure and secure their deployed code, but IaaS demands far more, including guest OS hardening and network controls.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.