CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A company subscribes to a SaaS-based customer relationship management (CRM) platform. Under the shared responsibility model, which of the following remains the customer's responsibility rather than the SaaS provider's?

  1. AManaging which employees have access to customer records
  2. BMaintaining the physical data center hardware
  3. CSecuring the hypervisor that runs virtual machines
  4. DPatching the underlying operating system
Show answer & explanation

Correct answer: A. Managing which employees have access to customer records

In a SaaS model, the provider manages nearly the entire stack, including infrastructure, OS, and application code, but the customer always retains responsibility for their own data and identity and access management, such as controlling which employees can view records.

Why the other options are wrong

  • B. Physical hardware maintenance is always the provider's responsibility in any cloud service model.
  • C. Hypervisor security is managed by the provider, as customers in SaaS have no visibility into virtualization infrastructure.
  • D. OS patching in SaaS is handled entirely by the provider since the customer has no access to the underlying servers.

Shared Responsibility Model

A framework defining which security and operational tasks are handled by the cloud provider versus the customer, varying by service model (IaaS, PaaS, SaaS).

  • Provider responsibility increases from IaaS to SaaS
  • Customer always retains responsibility for data and access management
  • Understanding the split prevents security gaps from assumed coverage

Memory trick: The customer always owns the keys to their own data, no matter the model

More Governance, Risk, Compliance and Security questions