Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?

⚠ Common exam trap

The trap is assuming the cloud provider encrypts all data by default; candidates often forget that in IaaS, data encryption at rest is a customer responsibility, not the provider's.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encryption of data at rest within the environment

In an IaaS model, the cloud provider manages the physical infrastructure, network, and hypervisor, while the customer is responsible for everything from the guest OS upward, including data encryption at rest. Encrypting data at rest within the environment is a customer responsibility because the customer controls the data and the encryption keys. The provider secures the underlying storage but does not automatically encrypt customer data unless the customer configures it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configuration of the hypervisor

    Why it's wrong here

    Hypervisor configuration sits with the cloud provider under IaaS, since it operates the virtualisation layer beneath the guest. It tempts because customers do configure guest OS settings and patching, but the hypervisor itself remains provider-managed; customer control begins at the operating system and above.

  • ✗

    Network infrastructure maintenance

    Why it's wrong here

    Physical network infrastructure maintenance belongs to the provider, which owns and operates the underlying fabric. It tempts because customers manage virtual networks, subnets, security groups and routing within their tenancy, but the physical routers, switches and cabling remain provider responsibility under IaaS.

  • ✗

    Physical security of data centers

    Why it's wrong here

    Physical data centre security is always the provider's responsibility, since the customer has no access to the facility. It tempts because customers remain accountable for the data they store and for logical access controls, yet guards, locks, cameras and environmental controls stay entirely with the cloud provider.

  • ✓

    Encryption of data at rest within the environment

    Why this is correct

    Under IaaS, the customer controls everything above the hypervisor, including guest operating systems, applications and data. Encrypting data at rest within that environment therefore falls to the customer, whereas the provider secures the physical hosts, network fabric and underlying storage infrastructure.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.