Which Document Identifies IaaS Security Controls in a CSP Contract?

A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?

  1. Statement of work
  2. Responsibility matrix Source Reference Answer
  3. Service-level agreement
  4. Master service agreement

Community Votes

B
67%
C
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question traps test-takers into conflating service performance guarantees with security accountability, testing precise vocabulary recognition around cloud governance artifacts.

This question evaluates your knowledge of cloud shared responsibility models and the specific contractual documents used to map security control ownership between a customer and a CSP. Community consensus confirms that responsibility matrices are the authoritative source for defining these division-of-labor details.

Candidates frequently choose the Service-Level Agreement (SLA), mistakenly assuming it covers security implementations when it actually defines uptime, throughput, and response time metrics rather than control ownership.

Community Discussion (6 comments)

Konversation 👍 1 Selected: B
B. Responsibility matrix "Identifies that responsibility for the implementation of security as applications, data, and workloads are transitioned into a cloud platform are shared between the customer and the cloud service provider (CSP)." CertMaster Learn CompTIA Card 262
itsgonnabemay 👍 2 Selected: C
Responsibility matrices are used internally for projects, while contracts between two independent parties outlining their expectations are SLAs.
9149f41 👍 1 Selected: B
The customer (company) and the CSP (Cloud Service Provider, e.g., Amazon, Google, etc.) have a contract. Both parties want to identify their responsibilities regarding security controls and implementation. Which contract document includes this responsibilities information? Clearly, it is written in the Responsibility Matrix.
Anyio 👍 2 Selected: B
B. Responsibility matrix Explanation: A responsibility matrix outlines which party (the customer or the cloud service provider) is responsible for implementing specific controls in a cloud environment, such as in an IaaS (Infrastructure as a Service) enclave. It is a key component in determining the division of responsibilities for security, compliance, and operational tasks. Why not the other options? A. Statement of work: A statement of work (SOW) defines the scope of a project, deliverables, and timelines but does not specifically address control implementation responsibilities. C. Service-level agreement: A service-level agreement (SLA) focuses on performance metrics (e.g., uptime, availability) but does not detail security control responsibilities.
umavaja 👍 2 Selected: B
Responsibility Matrix Responsibility Matrix, defines the specific roles and responsibilities of each party- CSP and Customer (Of IaaS model) . Details such as which controls are the responsibility of CSP (Physical security, hardware maintenance) and which are of the Customer(Data security, application configuration )
ProudFather 👍 1 Selected: C
A Service-Level Agreement (SLA) is the most likely document to contain information about the controls that should be implemented in an IaaS (Infrastructure as a Service) enclave. SLAs outline the specific services provided by the CSP and the agreed-upon performance and security standards. They typically include details on: Security controls: Such as access control mechanisms, encryption, and data protection measures. Service availability: Guarantees regarding uptime and performance. Support services: Levels of support provided by the CSP. Security incident response procedures: How security incidents will be handled and resolved.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Cloud Shared Responsibility

In Infrastructure as a Service (IaaS) environments, security is a shared obligation. The CSP secures the underlying physical infrastructure, networking hardware, and virtualization layer, while the customer retains responsibility for the guest operating system, middleware, applications, data, and identity management. Understanding this split is foundational to SY0-701 cloud objectives.

Why the Responsibility Matrix is Correct

A responsibility matrix (often aligned with a RACI chart or explicit shared responsibility model documentation) specifically delineates which party implements, manages, and maintains each security control. As noted by certified candidates referencing CompTIA study materials, this document directly answers "who owns what" during cloud transitions, making it the definitive source for IaaS enclave control mapping. Community discussions reinforce that while contracts outline expectations, the technical granularity of control implementation falls strictly under responsibility matrices.

Why Other Options Are Incorrect

  • Service-Level Agreement (SLA): An SLA focuses on measurable service performance, such as uptime percentages, latency thresholds, and incident response times. While it may reference compliance standards, it does not detail which specific security controls must be implemented by either party. Some forum users incorrectly associate SLAs with security because they govern "expectations between independent parties," but performance metrics differ from control ownership.
  • Statement of Work (SOW): This outlines project-specific deliverables, timelines, and scope for a particular engagement. It is tactical and temporary, not designed for ongoing security governance across a cloud deployment.
  • Master Service Agreement (MSA): The MSA establishes the overarching legal framework, liability limits, payment terms, and dispute resolution mechanisms. It governs the business relationship but omits granular technical control assignments.

Strategic Takeaway

When encountering vendor management questions, filter keywords like "controls," "ownership," "implementation," or "transition." These consistently point to responsibility matrices or shared responsibility frameworks, whereas "uptime," "performance," or "guarantees" signal SLAs.

Official Reference

  • NIST Special Publication 800-144: Guidelines on Security and Privacy in Public Cloud Computing
  • CIS Critical Security Controls v8: Cloud Security Implementation Guidance
  • CompTIA Security+ SY0-701 Official Objectives (Domains 1.0 & 4.0)

Exam Strategy

Always distinguish between operational metrics and security accountability when reading cloud contract questions. If the prompt emphasizes "who implements what" or "control ownership," immediately eliminate SLAs and MSAs in favor of responsibility matrices or shared responsibility models.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide