CompTIA Cloud Essentials+ (CLO-002)Cloud ConceptsMedium

A company is using a cloud provider for its web application. The provider's SLA states that they are responsible for the security of the underlying cloud infrastructure (physical facilities, network, compute, storage). The company, however, is responsible for the security of the application code, customer data, and network configurations within the virtual environment. This division of responsibility is characteristic of which cloud concept?

  1. ACloud Governance
  2. BShared Responsibility Model
  3. CCompliance Framework
  4. DCloud Security Alliance (CSA)
Show answer & explanation

Correct answer: B. Shared Responsibility Model

The Shared Responsibility Model clearly delineates the security obligations between the cloud provider ('security of the cloud') and the customer ('security in the cloud'), which is exactly what the scenario describes.

Why the other options are wrong

  • A. Cloud Governance refers to the policies and processes for managing cloud usage, not the division of security duties.
  • C. Compliance Frameworks are sets of rules or standards, not the model for dividing security responsibilities.
  • D. The Cloud Security Alliance (CSA) is an organization that promotes best practices, not a concept describing responsibility division.

Shared Responsibility Model

A framework that outlines the security responsibilities of the cloud provider and the cloud customer, varying based on the cloud service model (IaaS, PaaS, SaaS).

  • Provider: 'Security *of* the Cloud' (physical, infrastructure).
  • Customer: 'Security *in* the Cloud' (data, applications, configuration).
  • Responsibility shifts with service model (less for SaaS, more for IaaS).

Memory trick: SRM: Shared Responsibility Means 'Split Risks & Management'.

More Cloud Concepts questions