Question 180 of 1,013
SY0-701 Security Architecture Practice Question
A SaaS vendor hosts a customer relationship platform for multiple organizations. Your company wants to know which two responsibilities typically remain with the customer rather than the SaaS provider. Select two.
⚠ Common exam trap
Candidates often confuse infrastructure maintenance tasks (like patching databases or replacing hypervisors) with customer responsibilities, but in SaaS, the provider handles all underlying infrastructure while the customer only manages tenant-specific configurations and data governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assigning user roles and approving access within the tenant.
In a SaaS model, the customer retains administrative control over user identities, roles, and access permissions within their own tenant. The SaaS provider manages the underlying application and infrastructure, but the customer must configure role-based access control (RBAC) to enforce least privilege and approve access requests. This aligns with the shared responsibility model where identity and access management (IAM) at the application layer falls to the customer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assigning user roles and approving access within the tenant.
Why this is correct
Customer organizations usually remain responsible for deciding who gets access and what role each user receives inside the SaaS tenant. The provider supplies the platform, but the customer controls business authorization decisions. This is a core shared responsibility item because access mistakes often come from tenant configuration rather than provider infrastructure.
- ✓
Protecting the organization's data classification and sharing rules.
Why this is correct
Data classification and sharing decisions belong to the customer because the business defines what information is sensitive and who may see it. The SaaS provider may offer tools, but the customer must configure and enforce proper handling. This responsibility remains with the organization even when the data is stored in a vendor-managed platform.
- ✗
Patching the provider's underlying database engine.
Why it's wrong here
The SaaS provider is normally responsible for patching and maintaining the platform infrastructure, including underlying databases and host services. Customers do not directly manage those layers in a true SaaS model. Trying to treat that work as a customer duty misunderstands the service boundary.
- ✗
Maintaining the vendor's physical data center power and cooling.
Why it's wrong here
Physical data center operations are handled by the SaaS provider or its infrastructure partners. Customers do not manage power, cooling, or hardware replacement in the provider facility. Those responsibilities sit far below the customer control plane in the shared responsibility model.
- ✗
Replacing the provider's hypervisors during maintenance windows.
Why it's wrong here
Hypervisor maintenance is part of the provider's platform responsibility, not the customer’s. In SaaS, customers should focus on identity, data handling, and tenant configuration. Hardware and virtualization layers remain under the vendor's control and are not customer-administered tasks.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A team deploys a Linux virtual machine in IaaS and stores documents in a managed cloud object storage service. The provider secures datacenters, hardware, and the storage platform, but the organization still wants to reduce exposure. Which two tasks remain the organization's responsibility? Select two.
medium- ✓ A.Patch and harden the Linux virtual machine operating system.
- B.Replace the provider's datacenter controls with a customer-owned firewall appliance.
- C.Assume the provider will apply tenant-specific application permissions automatically.
- ✓ D.Configure IAM roles, bucket policies, and least-privilege access for the customer's resources.
- E.Rely on the cloud provider to classify the company's documents for compliance.
Why A: In an IaaS model, the customer is responsible for securing the operating system of the virtual machine, including applying patches and hardening configurations. The cloud provider secures the underlying hypervisor and physical infrastructure, but the customer must manage the OS-level security controls.
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.