SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses a cloud-based Customer Relationship Management (CRM) system that is delivered as Software-as-a-Service (SaaS). According to the shared responsibility model, which security responsibility is primarily handled by the customer?
⚠ Common exam trap
It's easy for candidates to assume the customer is responsible for all security aspects of a SaaS application, but SC-900 emphasizes that the provider handles infrastructure and platform security, leaving the customer with identity, data, and access management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user identities and controlling access to the CRM
In a SaaS model, the cloud provider is responsible for the security of the underlying infrastructure, including physical data centers, operating systems, and network controls. The customer retains responsibility for securing their own data and identities, which includes managing user accounts, enforcing authentication policies (e.g., Azure AD Multi-Factor Authentication), and controlling access to the CRM application via role-based access control (RBAC). Therefore, managing user identities and access is the customer's primary security responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical security of the data center hosting the CRM
Why it's wrong here
In a Software as a Service (SaaS) model, the cloud provider assumes full responsibility for the physical security of the data centers where the CRM application's infrastructure resides. This encompasses environmental controls, access management, and surveillance to protect the underlying hardware and facilities from unauthorized access or damage. The customer has no direct control or responsibility over these physical aspects, as they are consuming a fully managed service.
- ✓
Managing user identities and controlling access to the CRM
Why this is correct
The customer retains primary responsibility for managing user identities and controlling access within the SaaS CRM application. This involves provisioning user accounts, assigning appropriate roles and permissions, and configuring authentication methods, often integrating with their own corporate identity provider like Azure Active Directory. This ensures that only authorized personnel can access specific CRM functionalities and data, aligning with the principle of least privilege.
- ✗
Patching the underlying operating system of the CRM servers
Why it's wrong here
For a SaaS offering like a cloud-based CRM, the cloud provider is entirely responsible for patching and maintaining the underlying operating systems of the servers hosting the application. This crucial task ensures that security vulnerabilities are promptly addressed and system stability is maintained without any operational burden on the customer. The customer consumes the application without needing to manage the infrastructure layer.
- ✗
Ensuring network security for the CRM application's backend
Why it's wrong here
The cloud provider is responsible for ensuring the network security of the CRM application's backend infrastructure within a SaaS model. This encompasses managing network segmentation, configuring firewalls, implementing intrusion detection/prevention systems, and securing network connectivity between various backend components. The customer's responsibility typically begins at the application layer and their own network perimeter, not the provider's internal infrastructure.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.