CAS-004 Security Architecture Practice Question
An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Infrastructure as a Service (IaaS)
IaaS gives the customer control over OS, applications, and security configurations, while the provider manages the physical infrastructure. FedRAMP authorization can cover the IaaS layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software as a Service (SaaS)
Why it's wrong here
SaaS provides least customer control over security.
- ✓
Infrastructure as a Service (IaaS)
Why this is correct
Correct – IaaS offers maximum customer control over security.
- ✗
Platform as a Service (PaaS)
Why it's wrong here
PaaS abstracts the OS, limiting customer control.
- ✗
Function as a Service (FaaS)
Why it's wrong here
FaaS is even more abstracted than PaaS.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.