Courseiva
easyMultiple ChoiceObjective-mapped

Cloud Digital Leader Practice Question: Which term describes the model where the cloud…

Which term describes the model where the cloud provider is responsible for the security of the cloud infrastructure, while the customer is responsible for security within their own cloud environment (data, applications, access management)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Shared responsibility model

The shared responsibility model defines the division of security responsibilities between the cloud provider and the customer. Google secures the physical infrastructure, hardware, hypervisor, and core services. The customer secures what they put in the cloud: data classification, access control, application security, network configuration, and compliance. The boundary between provider and customer responsibility varies by service model (IaaS vs. PaaS vs. SaaS).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Zero trust security model

    Why it's wrong here

    Zero trust is a wrong answer because it is a security philosophy centered on 'never trust, always verify'—every request must be authenticated and authorized regardless of its origin. This model relies on continuous validation, least-privilege access, and micro-segmentation to mitigate lateral movement. Although Google Cloud supports zero-trust architectures, it does not by itself define the split of security responsibilities; that is a separate, higher-level governance concept.

  • Shared responsibility model

    Why this is correct

    The shared responsibility model is the correct framework because it explicitly partitions security duties between Google Cloud and the customer. Google Cloud protects physical infrastructure, the hypervisor, and foundational network components (security of the cloud), while the customer is responsible for securing their data, identity and access management, and workloads running in the cloud (security in the cloud). This division varies by service type—for IaaS customers patch OSs, whereas for SaaS the provider handles more—but the model itself is the standard for defining who owns which controls.

  • Defense in depth strategy

    Why it's wrong here

    Defense in depth is a wrong answer because it describes a layered security architecture—such as firewalls, intrusion prevention, endpoint detection, and data encryption—designed to protect resources even if one control fails. While Google Cloud and customers each implement such layers, the strategy does not allocate accountability between provider and customer. It is a design principle for resilience, not a contractual or operational framework that delineates security ownership.

  • Identity federation model

    Why it's wrong here

    Identity federation is a wrong answer because it is a technical mechanism for enabling single sign-on and centralized authentication using an external identity provider, typically via SAML or OIDC. It solves the problem of managing credentials across multiple systems, not the problem of dividing security duties between the cloud provider and the customer. Federation is a component within the customer's access-control responsibilities, but it is not a framework describing provider versus customer obligations.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.