GSEC Virtualization, Cloud, and AI Essentials Practice Question
A government agency is adopting a cloud service model for a new case management system that processes criminal justice information. The security architect must document which security responsibilities remain with the agency under the shared responsibility model for a Software as a Service (SaaS) deployment. (Choose two.)
⚠ Common exam trap
The trap here is assuming that because the provider secures the application, the customer no longer owns identity management and data classification, which remain customer duties in every cloud service model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user identities, authentication, and access permissions within the SaaS application.
Under the shared responsibility model for SaaS, the provider secures the application, runtime, and infrastructure, while the customer owns data governance and access control. Classifying data and deciding what may be stored are data-owner duties, and managing identities, authentication, and permissions controls who can reach that data. Infrastructure patching and physical security remain with the provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configuring the SaaS application's database engine parameters for optimal query performance.
Why it's wrong here
The database engine underpinning a SaaS application is managed by the provider. Customers typically have no direct access to database configuration parameters and cannot tune them. Performance tuning at that layer is a provider concern, while the customer focuses on configuration exposed through the application, such as workflows, roles, and retention settings.
- ✓
Managing user identities, authentication, and access permissions within the SaaS application.
Why this is correct
In SaaS, the provider manages the application, runtime, and infrastructure, but the customer remains responsible for who can access the application and what they can do. Identity lifecycle, authentication strength, and authorization assignments are customer-controlled and are a primary source of SaaS breaches. The agency must govern these to protect criminal justice information.
- ✓
Classifying data and determining which information may be stored in the SaaS environment.
Why this is correct
Data classification and residency decisions belong to the data owner, not the SaaS provider. The agency must determine sensitivity, apply handling rules, and ensure that criminal justice information is permitted in the chosen service. The provider supplies capabilities such as encryption and residency options, but the decision and accountability for what data enters the system remain with the agency.
- ✗
Maintaining the physical security of the data center facilities where the service runs.
Why it's wrong here
Physical security of data centers is always the cloud provider's responsibility, regardless of service model. The provider controls access to facilities, hardware, and environmental controls. The customer cannot influence or perform these functions, so they are not part of the customer's shared responsibility for a SaaS deployment.
- ✗
Patching the operating system and hypervisor that host the SaaS application.
Why it's wrong here
In a SaaS model, the provider owns and operates the underlying infrastructure, including operating systems, hypervisors, and the application runtime. Patching these layers is entirely the provider's responsibility. The customer has no access to these layers and cannot perform patching, so this is not a customer responsibility under the shared responsibility model.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.