712-50 exam dumps

712-50 practice question 213 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 213

Select 2

A newly appointed CISO is standardizing cloud governance after discovering inconsistent assumptions about who secures what across the organization. The company uses all three service models: an IaaS environment for custom applications, a PaaS service for application development, and a SaaS platform for customer relationship management. During a steering committee meeting, the CISO wants to identify which controls remain primarily the organization's responsibility across all three models under the shared responsibility model. Which TWO actions should the CISO state are still owned by the organization regardless of whether the workload is in IaaS, PaaS, or SaaS?

  1. A

    Defining and enforcing identity and access management policies, including user provisioning, privileged access, and MFA requirements

  2. B

    Patching and hardening the underlying physical hosts, hypervisors, and core managed platform components used by the cloud provider

  3. C

    Classifying data and defining protection requirements such as retention, encryption expectations, and access restrictions

  4. D

    Securing the provider's global network backbone, datacenter facilities, and environmental controls

  5. E

    Performing firmware updates on storage hardware used by the cloud provider to support customer workloads

Show answer and explanation

Correct answers: A, C

Explanation

Under the shared responsibility model, responsibility shifts depending on whether the service is IaaS, PaaS, or SaaS, but some governance responsibilities remain with the customer in every model. Two of the most important are identity and access management decisions and data governance decisions. In IaaS, the customer typically manages more of the stack, such as guest OS configuration, application security, and network configuration. In PaaS, the provider manages more of the platform, but the customer still owns application logic, identities, and data usage decisions. In SaaS, the provider manages most of the application stack, yet the customer still owns user access, tenant configuration, data classification, and compliance-related requirements. This aligns with major cloud-provider shared responsibility guidance and industry best practices from sources such as AWS Shared Responsibility Model documentation, Microsoft Learn guidance on shared responsibility in cloud services, Google Cloud shared responsibility guidance, and governance principles in frameworks such as NIST SP 800-145 and CSA cloud security guidance. From a CCISO perspective, the key leadership takeaway is that accountability for data protection, access governance, and policy enforcement does not disappear when services move to the cloud; it must be translated into effective governance, contracts, configuration standards, and oversight.

  • A. Correct.

    Correct. Identity and access management remains a core customer responsibility across IaaS, PaaS, and SaaS, even though implementation details vary by provider and service. The organization must decide who gets access, what level of privilege is appropriate, how accounts are provisioned and deprovisioned, and what authentication controls such as MFA are required. A common misunderstanding is that SaaS transfers all access-control responsibility to the provider; in reality, the provider typically offers IAM features, but the customer is accountable for configuring and governing access appropriately.

  • B. Incorrect.

    Incorrect. In the shared responsibility model, the provider is generally responsible for securing and maintaining the underlying infrastructure and managed service components, including physical hosts, hypervisors, and core platform layers. In IaaS, the customer is usually responsible for guest operating systems and workloads they manage, but not the provider's physical and virtualization stack. In PaaS and SaaS, even more of the technology stack is provider-managed. Choosing this option reflects the misconception that customer ownership of the application automatically extends down through all infrastructure layers.

  • C. Correct.

    Correct. Data classification and the definition of data protection requirements remain the organization's responsibility regardless of service model. The provider may supply encryption capabilities, retention settings, logging, and policy features, but the customer must determine the sensitivity of the data, regulatory obligations, retention periods, and which controls are required. This is a governance and risk ownership issue that does not transfer simply because the technology is cloud-hosted.

  • D. Incorrect.

    Incorrect. The provider is responsible for the security of the cloud, which includes datacenter facilities, physical security, environmental safeguards, and typically the core global network infrastructure. The customer may need assurance through contracts, certifications, and audit reports, but operational ownership of these controls remains with the provider. This option is plausible because CISOs must evaluate provider assurances, but evaluation is not the same as operating the control.

  • E. Incorrect.

    Incorrect. Firmware updates on provider-owned storage hardware are part of the provider's infrastructure operations and fall under the provider's responsibility in IaaS, PaaS, and SaaS. Customers may configure storage usage and data security settings, but they do not manage hardware maintenance in standard public cloud shared responsibility arrangements. Selecting this option confuses service consumption with infrastructure ownership.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam