easyMultiple ChoiceObjective-mapped
Cloud Digital Leader Practice Question: Which term describes the model where the cloud…
Which term describes the model where the cloud provider is responsible for the security of the cloud infrastructure, while the customer is responsible for security within their own cloud environment (data, applications, access management)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared responsibility model
The shared responsibility model defines the division of security responsibilities between the cloud provider and the customer. Google secures the physical infrastructure, hardware, hypervisor, and core services. The customer secures what they put in the cloud: data classification, access control, application security, network configuration, and compliance. The boundary between provider and customer responsibility varies by service model (IaaS vs. PaaS vs. SaaS).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Zero trust security model
Why it's wrong here
Zero trust is a wrong answer because it is a security philosophy centered on 'never trust, always verify'—every request must be authenticated and authorized regardless of its origin. This model relies on continuous validation, least-privilege access, and micro-segmentation to mitigate lateral movement. Although Google Cloud supports zero-trust architectures, it does not by itself define the split of security responsibilities; that is a separate, higher-level governance concept.
- ✓
Shared responsibility model
Why this is correct
The shared responsibility model is the correct framework because it explicitly partitions security duties between Google Cloud and the customer. Google Cloud protects physical infrastructure, the hypervisor, and foundational network components (security of the cloud), while the customer is responsible for securing their data, identity and access management, and workloads running in the cloud (security in the cloud). This division varies by service type—for IaaS customers patch OSs, whereas for SaaS the provider handles more—but the model itself is the standard for defining who owns which controls.
- ✗
Defense in depth strategy
Why it's wrong here
Defense in depth is a wrong answer because it describes a layered security architecture—such as firewalls, intrusion prevention, endpoint detection, and data encryption—designed to protect resources even if one control fails. While Google Cloud and customers each implement such layers, the strategy does not allocate accountability between provider and customer. It is a design principle for resilience, not a contractual or operational framework that delineates security ownership.
- ✗
Identity federation model
Why it's wrong here
Identity federation is a wrong answer because it is a technical mechanism for enabling single sign-on and centralized authentication using an external identity provider, typically via SAML or OIDC. It solves the problem of managing credentials across multiple systems, not the problem of dividing security duties between the cloud provider and the customer. Federation is a component within the customer's access-control responsibilities, but it is not a framework describing provider versus customer obligations.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Model
In IT and AI, a model is a trained mathematical representation that learns patterns from data to make predictions or decisions.
About these practice questions
This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.