TechKnowSurge
CompTIA Security+ 3.1 ISC2 CC 4.3 CompTIA Cloud+ 1.1 CompTIA A+ Core 1 4.1
InteractiveSecurityFree

Cloud Shared Responsibility Sorter

Sort cloud security tasks to the customer or the provider under IaaS, PaaS, SaaS and on-premises.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every item in this sorter names its model first, and the model decides the answer. The same task can land on either side: patching a hypervisor is the provider's job in IaaS and yours on-premises. The lesson this drills lays the service models out as a stack of layers — data, applications, the operating system, virtualization, servers, storage, networking, the data center — and each model draws a line across that stack. Everything below the line is the provider's, everything above it is yours, and that division is the shared responsibility model. On-premises there is no line, because there is no provider: you are in charge of everything, down to the lock on the server room door. IaaS draws the line just above virtualization. The provider runs the data center, networking, storage, servers and hypervisor, and hands you a virtual machine that behaves like one on your own desk, so its operating system, its applications and its data are yours. PaaS draws the line higher. The provider also runs the machine itself, and you keep only the application you deploy and the data behind it. SaaS draws it almost at the top. You manage really just your content — the inbox in a webmail account — and the rest is managed in the cloud. Two habits sort every item. First, ask whether you could log into that layer and change it; if you could not, it is not yours to secure. Second, remember the one constant: data is always the customer's. No model moves your data below the line, because the provider stores it without knowing what it is or who should see it. That is why the attack surface of a cloud service still includes you, and why choosing a provider is a security decision about a vendor you will rely on.

What you'll learn

Aligned to

CompTIA Security+
3.1 Compare and contrast security implications of different architecture models.
ISC2 CC
4.3 Understand cloud security
CompTIA Cloud+
1.1 Analyze the different cloud models to design the best solution to support business requirements.
CompTIA A+ Core 1
4.1 Summarize cloud-computing concepts.

Key terms

Shared Responsibility Model
A framework that defines how security responsibilities are divided between a cloud service provider and its customers across different service and deployment models.
Infrastructure as a Service
IaaS
A cloud service model that provides virtualized computing infrastructure over the internet.
Platform as a Service
PaaS
A cloud service model that provides a platform for developing, running, and managing applications without managing infrastructure.
Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Cloud Service Provider
CSP
A company that offers computing services in the cloud, including IaaS, PaaS, SaaS, and colocation options.
On-Premises
An infrastructure deployment model in which hardware and software are hosted locally within an organization's own facilities rather than in a cloud provider's data center. On-premises deployments give organizations full control over their security posture.
Cloud Computing
The delivery of computing services including servers, storage, and software over the internet on a pay-as-you-go basis.
Hypervisor
Software that creates and manages virtual machines by abstracting hardware resources.
Virtual Machine
VM
A software emulation of a physical computer that runs an operating system and applications.
Data Center
A facility that houses computing infrastructure such as servers, storage, and networking equipment used to deliver IT services.
Physical Security
The use of tangible controls — such as locks, barriers, surveillance cameras, and access badges — to protect facilities, hardware, and infrastructure from unauthorized physical access, theft, or damage.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →