Skip to content
Tech Interview Prep home
Technical interview guide

The Shared Responsibility Model

What the cloud provider secures versus what the customer is responsible for — and why most cloud breaches fall on the customer's side.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed

Scope: AWS, Microsoft Azure, Google Cloud, and NIST shared-responsibility guidance current 2026-09-01.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Build a shared-responsibility matrix for a production workload.

QA-2

Assess responsibility for an IaaS web application.

QA-3

Assess responsibility for a managed database service.

QA-4

Assess responsibility for a SaaS business application.

QA-5

What is the core distinction between security 'of' the cloud and security 'in' the cloud?

QA-6

How does customer vs provider responsibility for encryption and data protection differ across IaaS, PaaS, and SaaS?

QA-7

Design reliability under the shared-responsibility model.

QA-8

Handle a provider outage affecting a critical workload.

QA-9

Under the shared responsibility model, who is responsible for patch management across Infrastructure as a Service (IaaS) versus Platform as a Service (PaaS)?

QA-10

Map data protection responsibilities in a managed cloud service.

QA-11

Map identity and access responsibility across a federated cloud tenant.

QA-12

Review a serverless architecture through shared responsibility.

QA-13

Assess a marketplace appliance or managed partner service.

QA-14

Resolve an ambiguous responsibility for a security control.

QA-15

Operationalize shared responsibility through policy as code.

QA-16

Prepare for a provider compliance report expiration or qualified finding.

QA-17

Design provider support access and break-glass governance.

QA-18

Plan cloud-service deprecation or responsibility shift.

QA-19

Use shared responsibility in a cloud threat model.

QA-20

Map shared responsibility for AI services in the cloud.

QA-21

Plan a secure and verifiable exit from a cloud provider.

QA-22

Measure whether shared responsibility is working operationally.

QA-23

Review a proposal to transfer every security task to a managed service.

QA-24

Define responsibility for cloud logging and forensic evidence.

QA-25

Resolve customer misconfiguration enabled by an unsafe service default.