712-50 exam dumps

712-50 practice question 212 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 212

Select 2

A newly appointed CISO is standardizing security accountability across three cloud services used by the enterprise: an IaaS environment hosting custom Linux-based applications, a PaaS service used by developers to deploy managed web applications, and a SaaS CRM platform used by sales staff. During a steering committee meeting, business leaders ask which security responsibilities remain with the enterprise across all three service models under the shared responsibility model. Which TWO responsibilities should the CISO identify as consistently owned by the customer organization?

  1. A

    Configuring user access, identity governance, and data access policies within each cloud service

  2. B

    Patching the physical hosts, storage arrays, and hypervisor layer used by the cloud provider

  3. C

    Classifying sensitive business data and defining protection requirements such as encryption, retention, and sharing restrictions

  4. D

    Maintaining the managed runtime, middleware, and underlying operating system for the PaaS platform

Show answer and explanation

Correct answers: A, C

Explanation

The shared responsibility model varies by cloud service model, but some responsibilities remain with the customer across IaaS, PaaS, and SaaS. Two of the most consistent customer-owned areas are identity/access governance and data governance. In all three models, the provider secures the cloud infrastructure itself to varying extents, while the customer is responsible for security in the cloud that relates to its users, data, configurations, and business use of the service. For IaaS, the customer typically manages guest operating systems, applications, data, and network configurations; for PaaS, responsibility shifts more toward application code, identities, configurations, and data; for SaaS, the customer still owns user administration, data classification, tenant configuration, and policy enforcement even though the provider manages most of the application stack. This aligns with common cloud guidance from major providers and industry best practices, including the principle that customers retain responsibility for data classification, access control decisions, and compliance obligations regardless of deployment model.

  • A. Correct.

    Correct. In IaaS, PaaS, and SaaS, the customer organization remains responsible for governing identities, roles, entitlements, and how users are authorized to access data and functions. While providers may supply IAM features, the enterprise must decide who should have access, enforce least privilege, and review access rights. This is a consistent customer responsibility across all three service models.

  • B. Incorrect.

    Incorrect. Physical infrastructure security and maintenance of the underlying hardware and virtualization stack are generally the cloud provider's responsibility in IaaS, PaaS, and SaaS. A common misconception is that because IaaS gives the customer more control, the customer also patches the provider's hypervisor or physical hosts. In practice, the provider secures and maintains the facilities, hardware, and core virtualization layer.

  • C. Correct.

    Correct. Data ownership and governance remain with the customer regardless of service model. The enterprise must classify its information, determine applicable regulatory and contractual requirements, and define controls such as encryption requirements, retention periods, acceptable sharing, and handling procedures. Even when a provider offers security features, the customer decides how sensitive data should be protected and used.

  • D. Incorrect.

    Incorrect. In PaaS, the provider typically manages the runtime, middleware, operating system, and much of the platform stack. The customer is usually responsible for the security of its applications, code, data, and configuration on the platform, but not for maintaining the managed runtime and OS components. This option reflects confusion between IaaS and PaaS responsibilities.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam