2026 Licensing & Certification Curricula (Securities, Cloud, IT, Real Estate, Bar & CPA) are now live
Chapter 3 • Domain 33.1

3.1 Enterprise Cloud Architecture and Shared Responsibility Models

Differentiate security boundaries across IaaS, PaaS, and SaaS cloud deployment models, managing IAM, hypervisors, and data protection.

🎯 Key CompTIA Security+ Exam Takeaways

  • In Infrastructure as a Service (IaaS), the CSP manages physical infrastructure and virtualization hypervisors; the customer owns the guest OS, networking, and applications.
  • In Platform as a Service (PaaS), the CSP manages the hardware, hypervisor, OS, and runtime; the customer configures application code and data.
  • In Software as a Service (SaaS), the CSP manages the entire stack; the customer is responsible solely for user access management and data classification.
  • The customer ALWAYS retains ultimate accountability for data classification, data governance, and access authorization across every cloud model.

Modern enterprise IT architecture has largely transitioned from on-premises datacenters to cloud environments. Understanding security boundaries requires mastering the Cloud Shared Responsibility Model across Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).

In IaaS (e.g., AWS EC2, Azure VMs), the Cloud Service Provider (CSP) maintains physical datacenter facilities, power, cooling, physical servers, and the virtualization hypervisor. The customer is responsible for configuring, patching, and securing the guest operating system, installing applications, defining network security group firewall rules, and managing IAM policies. In PaaS (e.g., AWS Elastic Beanstalk, Azure App Services), the CSP also manages and patches the underlying operating system and database engines, leaving the customer responsible only for their custom application code and data.

In SaaS (e.g., Microsoft 365, Salesforce), the vendor operates and maintains the entire hardware, software, and application stack. However, regardless of whether an enterprise deploys IaaS, PaaS, or SaaS, the customer always retains ultimate legal accountability for classifying data, managing user identities, enforcing multi-factor authentication, and ensuring compliance with privacy regulations.

⚠️ Common Pearson VUE Exam Traps

  • Assuming migrating to public cloud transfers all security liability to the CSP; under the Shared Responsibility Model, customers remain fully responsible for data protection and IAM.
  • Thinking SaaS requires patching operating systems; SaaS customers have no access to the underlying OS or infrastructure.

Knowledge Checkpoint

Knowledge Checkpoint • Section 3.1

An enterprise migrates its customer billing application to a public cloud Infrastructure as a Service (IaaS) provider. According to the Cloud Shared Responsibility Model, which security task remains the sole responsibility of the customer rather than the cloud service provider (CSP)?