Medium1 markMultiple Choice
Area I: Information SystemsCloud ComputingPaaSPatch Management

CPA · Question 38 · Area I: Information Systems

A company uses a 'Platform as a Service' (PaaS) environment to develop and host its web application. The auditor asks for evidence of 'patch management'. Which response from the client is most appropriate regarding the underlying operating system?

Answer options:

A.

The client provides a link to the cloud provider's compliance portal showing they handle OS patching.

B.

The client provides logs of their own WSUS (Windows Server Update Services) server.

C.

The client states that patching is not required in the cloud.

D.

The client provides the source code of the application.

How to approach this question

Recall the Shared Responsibility Model for PaaS. Provider = Hardware + OS. Customer = App + Data.

Full Answer

A.The client provides a link to the cloud provider's compliance portal showing they handle OS patching.✓ Correct
A
In a PaaS model, the cloud service provider is responsible for managing the underlying infrastructure, including the operating system and its patches. The customer is responsible for the application they build on top of it.

Common mistakes

Confusing PaaS with IaaS.

Practice the full CPA ISC Practice Exam

82 questions · hints · full answers · grading

More questions from this exam