CCSP Cloud Concepts, Architecture, and Design Practice Question
An organization needs to migrate a legacy application to the cloud. The application requires full control over the operating system, middleware, and runtime. The team wants to minimize management overhead while retaining OS-level access. Which cloud service model is most appropriate?
⚠ Common exam trap
CCSP often tests the shared responsibility boundary, tricking candidates into picking PaaS when the requirement explicitly mentions OS-level control, which only IaaS provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IaaS
IaaS provides virtualized compute, storage, and networking where the customer manages the OS, middleware, and runtime while the provider manages the underlying physical infrastructure. This matches the requirement for full OS-level control with reduced management overhead compared to on-premises. SaaS, PaaS, and FaaS abstract away the OS, so they cannot satisfy the need for OS-level access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IaaS
Why this is correct
IaaS provides raw compute, storage, and networking while the customer retains full control of the operating system, middleware, and runtime. The provider manages only the underlying infrastructure, satisfying the OS-level access requirement while offloading hardware management, minimising overhead.
- ✗
SaaS
Why it's wrong here
SaaS delivers a complete application where the provider manages everything down to the application layer, so the customer gets no operating system or runtime control. It would be correct when the requirement is consuming finished software with minimal administration, not retaining OS-level access for a legacy application.
- ✗
FaaS
Why it's wrong here
FaaS runs event-triggered code with the provider managing the operating system, runtime and scaling, so no OS-level access is exposed. It would be correct for stateless, event-driven functions where management overhead must be near zero, not for a legacy application needing control of the OS and middleware.
- ✗
PaaS
Why it's wrong here
PaaS abstracts the operating system and runtime, so the customer cannot control or access them; only the deployed application and its configuration are managed. It would be correct when the requirement is developing on a managed platform without OS administration, not retaining OS-level access.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.