Who Secures the Database in an IaaS Shared Responsibility Model?
Which of the following roles, according to the shared responsibility model, is responsible for securing the company’s database in an IaaS model for a cloud environment?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of the IaaS shared responsibility boundary, where candidates often mistakenly select a specific job title (DBA) instead of recognizing that the client/customer organization holds ultimate responsibility for data security.
In Infrastructure as a Service (IaaS), the shared responsibility model dictates that the cloud customer (client) secures all data, applications, and configurations running above the provider-managed infrastructure. Candidates must distinguish between organizational roles like DBAs and the overarching contractual responsibility assigned to the client entity.
Many candidates choose D (DBA) because they focus on the operational role rather than the contractual framework; however, the shared responsibility model assigns accountability to the entire client organization, not just individual job functions.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the IaaS Shared Responsibility Boundary
In cloud computing, the shared responsibility model divides security duties between the cloud provider and the customer. For Infrastructure as a Service (IaaS), the provider secures the underlying hardware, virtualization layer, networking, and physical data centers. Everything above that layer—including the operating system, middleware, runtime, applications, and critically, the data itself—falls squarely under the client’s responsibility. As noted by the community, this means configuring firewalls, managing access controls, patching the OS, and encrypting database contents are tasks the customer must handle.Why the Client Holds Ultimate Accountability
The term "Client" in this context refers to the cloud customer organization, which encompasses all internal teams, including Database Administrators (DBAs), security engineers, and developers. While a DBA may perform the hands-on configuration and maintenance, the shared responsibility model does not assign liability or ownership to specific job titles; it assigns it to the contracting party. Therefore, selecting "DBA" misses the broader architectural and compliance perspective tested by CompTIA Security+. The client organization is legally and operationally accountable for securing its data assets regardless of who executes the daily tasks.Evaluating the Distractors
Option B (Third-party vendor) is incorrect unless specifically contracted for managed services, which isn't indicated in the scenario. Option C (Cloud provider) handles the "security OF the cloud," not "security IN the cloud." Their responsibilities end at the hypervisor/infrastructure layer in IaaS. Option D (DBA) is a common trap, as candidates confuse operational execution with strategic responsibility. The exam consistently emphasizes that accountability rests with the customer/client entity when evaluating cloud deployment models.Official Reference
Exam Strategy
When answering cloud security questions, always identify the deployment model first (IaaS, PaaS, or SaaS) to determine the exact responsibility boundary. Remember that the shared responsibility model assigns accountability to the customer organization ("Client"), not to individual job titles, and focus on who owns the data and applications rather than who performs the daily administrative tasks.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →