StudyToCert

All certifications / Cloud+ / Lessons

CompTIA Cloud+ CV0-004 · Domain 1: Cloud architecture

Cloud service models (IaaS, PaaS, SaaS, FaaS) and the shared responsibility model

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A cloud service model describes how much of the technology stack the provider runs for you and how much you still run yourself. Cloud+ expects you to place any service on that spectrum quickly, because the model decides who patches what, who secures what and who gets paged when something breaks.

On-premown DCIaaSEC2, VMPaaSRDS, App SvcSaaSM365Data and accessYouYouYouYouApplicationsYouYouYouProviderRuntimeYouYouProviderProviderOperating systemYouYouProviderProviderVirtualizationYouProviderProviderProviderServers, storageYouProviderProviderProviderNetworkingYouProviderProviderProviderDatacenterYouProviderProviderProviderYou: security in the cloudProvider: of the cloudYour data, identities and access are always yours
Shared responsibility model: on-premises, IaaS, PaaS and SaaS
Technology stackProvider deliversApplicationDataRuntimeOperating systemVirtualizationServers and storageNetworkingIaaSEC2, VMsPaaSApp ServiceSaaSMicrosoft 365Above each bracket: yours · FaaS: just code
IaaS, PaaS and SaaS: how much of the stack you rent

Infrastructure as a service (IaaS) gives you virtual machines, virtual networks and block storage. The provider runs the data center, the physical hosts and the hypervisor; you install and patch the operating system, the runtime, your applications and your data. Platform as a service (PaaS) moves the operating system and runtime to the provider: you deploy code or a container to a managed application platform or use a managed database, and you manage only the application, its configuration and its data. Software as a service (SaaS) is a finished application such as web email or a CRM system; you manage users, settings and the data you put in it. Function as a service (FaaS), often called serverless compute, runs short pieces of code in response to events. You supply the function code and its configuration, such as memory and timeout, and the provider handles servers, scaling and patching, charging per invocation and execution time.

The shared responsibility model is the agreement that follows from those choices. The provider is always responsible for security of the cloud: physical buildings, hardware, the global network and the virtualization layer. The customer is always responsible for security in the cloud: their data, who has access to it (identity and access management) and how services are configured. The layers in between shift with the model. In IaaS you patch the guest operating system; in PaaS the provider does; in SaaS you still decide who can sign in and what data is shared.

Two points trip people up. First, responsibility for data and identities never moves to the provider, even in SaaS. A publicly readable storage bucket or a user without MFA is a customer failure. Second, managed does not mean unconfigured: a managed database still needs you to choose network exposure, encryption keys, backups and user accounts.

Key terms

IaaS
Infrastructure as a service: the provider supplies virtual compute, storage and networking, and the customer manages the operating system and everything above it.
PaaS
Platform as a service: the provider also runs the operating system and runtime, so the customer deploys and manages only application code and data.
SaaS
Software as a service: a complete application delivered over the internet; the customer manages users, settings and data.
FaaS
Function as a service: event-driven code that runs on demand without servers for the customer to manage, billed per execution.
Shared responsibility model
The division of security and operational duties between provider and customer, which shifts with the service model.
Real-world example

A company moves its intranet from a self-managed VM to a PaaS web app service. The operations team no longer patches the Windows guest or the web server runtime, but they still configure TLS certificates, restrict who can deploy, store connection strings securely and back up the application's database.

Exam tip: When a question asks who is responsible for something, first identify the service model. Data, identities, access policies and configuration always stay with the customer; physical security and the hypervisor always stay with the provider.

Check yourself

In an IaaS deployment, who applies security patches to the guest operating system?

The customer. In IaaS the provider stops at the hypervisor and physical hosts; the guest OS and everything above it is the customer's job.

A SaaS file-sharing tenant leaks data because a folder was shared publicly. Whose responsibility was that?

The customer's. Data and access configuration remain customer responsibilities in every service model, including SaaS.

Which model charges per invocation and runs code only when an event occurs?

FaaS (serverless functions).

Study Cloud+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud+ study plan