Courseiva
Security ArchitectureeasyMultiple SelectObjective-mapped

SY0-701 Security Architecture Practice Question

A company uses a SaaS email platform. The provider manages the servers and application code. Which two tasks remain the company's responsibility? Select two.

⚠ Common exam trap

The SY0-701 exam often tests the misconception that 'patching' is always the customer's job, but in SaaS the provider handles all infrastructure patching, while the customer's responsibility is limited to configuration and data governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring who can access company mailboxes and administrative roles.

In a SaaS model, the customer retains administrative control over user access and role-based permissions. This includes configuring mailbox permissions, setting up multi-factor authentication, and managing administrative roles within the provider's interface. The provider handles the underlying infrastructure, but identity and access management (IAM) remains the customer's responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configuring who can access company mailboxes and administrative roles.

    Why this is correct

    The provider manages the mail system infrastructure, but access control remains the customer's responsibility under the SaaS shared responsibility model. The company must create and manage user accounts, assign mailbox permissions, configure administrative roles, and enforce least privilege via role-based access control. This includes implementing conditional access policies, multi-factor authentication, and periodic access reviews to prevent privilege creep.

  • Applying security patches to the provider's mail servers.

    Why it's wrong here

    Applying security patches to the provider's mail servers is a task reserved for the SaaS vendor, not the customer. The patching lifecycle of the underlying mail application, operating systems, and supporting infrastructure is entirely managed by the provider to protect all tenants. Customers have no administrative or shell access to those servers and instead focus on client-side security, like configuring Outlook or securing the browser.

  • Deciding what data may be stored in the service and how it is classified.

    Why this is correct

    Data governance remains the customer's obligation even when the service is hosted by a SaaS vendor. The organization must decide which data types are permissible, classify information according to sensitivity, and set retention and deletion policies that align with legal or regulatory requirements. The provider simply stores and processes the data under contractual terms; the customer ultimately owns the risk and liability for incorrect classification or unauthorized data storage.

  • Replacing failed provider storage disks.

    Why it's wrong here

    Replacing failed storage disks in the provider's infrastructure is part of the provider's operational duty, not the customer's. SaaS customers consume the service at the application level and have no physical or logical access to the underlying storage array, making hardware maintenance impossible and contractually prohibited. Hardware reliability is guaranteed via the provider's SLAs, and any failure is transparently handled by the vendor without customer involvement.

  • Hardening the provider's hypervisor.

    Why it's wrong here

    Hardening the provider's hypervisor is a core security function performed by the cloud or SaaS provider, since the hypervisor is the virtualization layer that isolates tenants from one another. Customers are never granted access to the hypervisor console or its configuration, and attempting to alter it would require breaching the provider's trusted boundary. In practice, the customer's security efforts should be directed toward application-level settings, such as message encryption, malware filtering, and user behavior, rather than the hypervisor.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses a SaaS file-sharing platform for employee documents. Which action is the company's responsibility, not the provider's?

easy
  • A.Patching the vendor's application servers.
  • B.Setting user sharing permissions and access controls for company data.
  • C.Replacing failed disks in the provider's storage cluster.
  • D.Maintaining the cloud provider's identity center and hypervisor.

Why B: In a SaaS model, the provider manages the underlying infrastructure, including application servers, storage, and hypervisors. The customer is responsible for configuring access controls and permissions for their own data within the application. Option B correctly identifies this shared responsibility boundary.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.