CAS-004 Security Architecture Practice Question
An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?
⚠ Common exam trap
CAS-005 often tests the inverse relationship between abstraction level and customer control — candidates may assume PaaS or SaaS offers more control because it 'does more,' when in fact IaaS gives the customer the most configuration responsibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Infrastructure as a Service (IaaS)
IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical infrastructure, hypervisor, and network fabric. Under FedRAMP, the provider's authorization covers the underlying infrastructure, but the customer retains responsibility for configuring and securing everything above the hypervisor — offering the most security configuration control among the listed models while still leveraging the provider's FedRAMP package.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software as a Service (SaaS)
Why it's wrong here
SaaS leaves security configuration almost entirely with the provider, so the customer cannot control underlying settings; only tenant-level options exist. It is tempting because SaaS carries the provider's FedRAMP authorisation with minimal effort, and would be right when the workload is a standard application needing no custom security configuration.
- ✓
Infrastructure as a Service (IaaS)
Why this is correct
IaaS lets the organisation manage its own operating systems, middleware and applications, giving maximum control over security configuration, while the provider's FedRAMP authorisation covers the underlying infrastructure. PaaS and SaaS shift more configuration responsibility to the provider, reducing customer control.
- ✗
Platform as a Service (PaaS)
Why it's wrong here
PaaS abstracts the operating system and runtime, so the customer cannot harden patching, host firewalls or kernel settings — control the stem demands. It is tempting because PaaS inherits the provider's FedRAMP authorisation with less operational burden, and suits teams wanting managed runtimes rather than infrastructure-level security configuration.
- ✗
Function as a Service (FaaS)
Why it's wrong here
FaaS abstracts the runtime entirely, leaving the customer no control over operating system, patching or network security configuration. It is tempting because the provider's FedRAMP authorisation covers the platform, but IaaS inherits that authorisation while retaining customer control of the security stack.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.