ITPEC FE Morning October 2018 Question 43
ITPEC FE Morning October 2018 — Question 43 of 80
SaaS Security Management — In SaaS, the provider handles system construction, development, and infrastructure, but the customer remains responsible for access management, security policies, and operational procedures.
The correct answer is b): no system construction is needed, and neither defining security requirements for application development nor designing storage for system logs is required — the SaaS provider handles all of that.
Why not the others:
- a) Wrong — access management (passwords, complexity policies) is always the customer's responsibility, even in SaaS.
- c) Wrong — operational procedures for failures and backups still require customer consideration (e.g., data export plans, failover procedures).
- d) Wrong — security management rules and administrator assignment are always the customer's responsibility.
Key rule: SaaS removes construction and development responsibilities, but access control, security governance, and operational readiness remain with the customer.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.