CAS-004 Security Architecture Practice Question
In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?
⚠ Common exam trap
CAS-005 often tests the shared responsibility model by presenting responsibilities that seem like they could be either party's. The trap is assuming the provider handles data encryption because they offer encryption tools, but the customer must still configure and manage it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data classification and encryption
In the shared responsibility model for cloud security, the customer is always responsible for the security of their data, including classification and encryption. This includes determining data sensitivity, applying appropriate encryption at rest and in transit, and managing encryption keys. The cloud provider is responsible for security of the cloud (physical, network, hypervisor), while the customer is responsible for security in the cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data classification and encryption
Why this is correct
Data classification and encryption remain customer responsibilities because the provider cannot determine sensitivity or manage keys without the tenant's context. In the shared responsibility model, the customer always owns data governance, including classifying information and controlling encryption keys, while Microsoft Entra ID and the underlying infrastructure stay with the provider.
- ✗
Physical security of data centers
Why it's wrong here
Physical security of data centres remains with the cloud provider under the shared responsibility model, since the customer never controls those facilities. It is tempting because customers must secure their own physical assets, which would be correct for on-premises infrastructure they own and operate directly.
- ✗
Network infrastructure security
Why it's wrong here
Network infrastructure security, including the underlying routers, switches and cabling, is managed by the cloud provider; the customer secures what they deploy on top, such as data, identities and configurations. It is tempting because network security is a customer duty in on-premises environments, where they own that infrastructure.
- ✗
Hypervisor security
Why it's wrong here
Hypervisor security sits with the cloud provider, as the hypervisor underpins the provider's virtualisation layer and customers cannot access it. It is tempting because hypervisor hardening is a customer task in private virtualisation they host themselves, where they control the underlying platform.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.