Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?

⚠ Common exam trap

CAS-005 often tests the inverse relationship between abstraction level and customer control — candidates may assume PaaS or SaaS offers more control because it 'does more,' when in fact IaaS gives the customer the most configuration responsibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Infrastructure as a Service (IaaS)

IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical infrastructure, hypervisor, and network fabric. Under FedRAMP, the provider's authorization covers the underlying infrastructure, but the customer retains responsibility for configuring and securing everything above the hypervisor — offering the most security configuration control among the listed models while still leveraging the provider's FedRAMP package.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Software as a Service (SaaS)

    Why it's wrong here

    SaaS leaves security configuration almost entirely with the provider, so the customer cannot control underlying settings; only tenant-level options exist. It is tempting because SaaS carries the provider's FedRAMP authorisation with minimal effort, and would be right when the workload is a standard application needing no custom security configuration.

  • ✓

    Infrastructure as a Service (IaaS)

    Why this is correct

    IaaS lets the organisation manage its own operating systems, middleware and applications, giving maximum control over security configuration, while the provider's FedRAMP authorisation covers the underlying infrastructure. PaaS and SaaS shift more configuration responsibility to the provider, reducing customer control.

  • ✗

    Platform as a Service (PaaS)

    Why it's wrong here

    PaaS abstracts the operating system and runtime, so the customer cannot harden patching, host firewalls or kernel settings — control the stem demands. It is tempting because PaaS inherits the provider's FedRAMP authorisation with less operational burden, and suits teams wanting managed runtimes rather than infrastructure-level security configuration.

  • ✗

    Function as a Service (FaaS)

    Why it's wrong here

    FaaS abstracts the runtime entirely, leaving the customer no control over operating system, patching or network security configuration. It is tempting because the provider's FedRAMP authorisation covers the platform, but IaaS inherits that authorisation while retaining customer control of the security stack.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.