Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company uses a cloud-based Customer Relationship Management (CRM) system that is delivered as Software-as-a-Service (SaaS). According to the shared responsibility model, which security responsibility is primarily handled by the customer?

⚠ Common exam trap

It's easy for candidates to assume the customer is responsible for all security aspects of a SaaS application, but SC-900 emphasizes that the provider handles infrastructure and platform security, leaving the customer with identity, data, and access management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Managing user identities and controlling access to the CRM

In a SaaS model, the cloud provider is responsible for the security of the underlying infrastructure, including physical data centers, operating systems, and network controls. The customer retains responsibility for securing their own data and identities, which includes managing user accounts, enforcing authentication policies (e.g., Azure AD Multi-Factor Authentication), and controlling access to the CRM application via role-based access control (RBAC). Therefore, managing user identities and access is the customer's primary security responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Physical security of the data center hosting the CRM

    Why it's wrong here

    In a Software as a Service (SaaS) model, the cloud provider assumes full responsibility for the physical security of the data centers where the CRM application's infrastructure resides. This encompasses environmental controls, access management, and surveillance to protect the underlying hardware and facilities from unauthorized access or damage. The customer has no direct control or responsibility over these physical aspects, as they are consuming a fully managed service.

  • Managing user identities and controlling access to the CRM

    Why this is correct

    The customer retains primary responsibility for managing user identities and controlling access within the SaaS CRM application. This involves provisioning user accounts, assigning appropriate roles and permissions, and configuring authentication methods, often integrating with their own corporate identity provider like Azure Active Directory. This ensures that only authorized personnel can access specific CRM functionalities and data, aligning with the principle of least privilege.

  • Patching the underlying operating system of the CRM servers

    Why it's wrong here

    For a SaaS offering like a cloud-based CRM, the cloud provider is entirely responsible for patching and maintaining the underlying operating systems of the servers hosting the application. This crucial task ensures that security vulnerabilities are promptly addressed and system stability is maintained without any operational burden on the customer. The customer consumes the application without needing to manage the infrastructure layer.

  • Ensuring network security for the CRM application's backend

    Why it's wrong here

    The cloud provider is responsible for ensuring the network security of the CRM application's backend infrastructure within a SaaS model. This encompasses managing network segmentation, configuring firewalls, implementing intrusion detection/prevention systems, and securing network connectivity between various backend components. The customer's responsibility typically begins at the application layer and their own network perimeter, not the provider's internal infrastructure.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.