Which Document Identifies IaaS Security Controls in a CSP Contract?
A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question traps test-takers into conflating service performance guarantees with security accountability, testing precise vocabulary recognition around cloud governance artifacts.
This question evaluates your knowledge of cloud shared responsibility models and the specific contractual documents used to map security control ownership between a customer and a CSP. Community consensus confirms that responsibility matrices are the authoritative source for defining these division-of-labor details.
Candidates frequently choose the Service-Level Agreement (SLA), mistakenly assuming it covers security implementations when it actually defines uptime, throughput, and response time metrics rather than control ownership.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Cloud Shared Responsibility
In Infrastructure as a Service (IaaS) environments, security is a shared obligation. The CSP secures the underlying physical infrastructure, networking hardware, and virtualization layer, while the customer retains responsibility for the guest operating system, middleware, applications, data, and identity management. Understanding this split is foundational to SY0-701 cloud objectives.Why the Responsibility Matrix is Correct
A responsibility matrix (often aligned with a RACI chart or explicit shared responsibility model documentation) specifically delineates which party implements, manages, and maintains each security control. As noted by certified candidates referencing CompTIA study materials, this document directly answers "who owns what" during cloud transitions, making it the definitive source for IaaS enclave control mapping. Community discussions reinforce that while contracts outline expectations, the technical granularity of control implementation falls strictly under responsibility matrices.Why Other Options Are Incorrect
- Service-Level Agreement (SLA): An SLA focuses on measurable service performance, such as uptime percentages, latency thresholds, and incident response times. While it may reference compliance standards, it does not detail which specific security controls must be implemented by either party. Some forum users incorrectly associate SLAs with security because they govern "expectations between independent parties," but performance metrics differ from control ownership.
- Statement of Work (SOW): This outlines project-specific deliverables, timelines, and scope for a particular engagement. It is tactical and temporary, not designed for ongoing security governance across a cloud deployment.
- Master Service Agreement (MSA): The MSA establishes the overarching legal framework, liability limits, payment terms, and dispute resolution mechanisms. It governs the business relationship but omits granular technical control assignments.
Strategic Takeaway
When encountering vendor management questions, filter keywords like "controls," "ownership," "implementation," or "transition." These consistently point to responsibility matrices or shared responsibility frameworks, whereas "uptime," "performance," or "guarantees" signal SLAs.Official Reference
- NIST Special Publication 800-144: Guidelines on Security and Privacy in Public Cloud Computing
- CIS Critical Security Controls v8: Cloud Security Implementation Guidance
- CompTIA Security+ SY0-701 Official Objectives (Domains 1.0 & 4.0)
Exam Strategy
Always distinguish between operational metrics and security accountability when reading cloud contract questions. If the prompt emphasizes "who implements what" or "control ownership," immediately eliminate SLAs and MSAs in favor of responsibility matrices or shared responsibility models.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →