Objective 5.1

CDL

Describe fundamental cloud security concepts.

Objective 5.1 sits in Trust and Security with Google Cloud, which carries 18% of the Cloud Digital Leader exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.

Objective title verbatim from the official objectives. Google Cloud exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

5-1Trust and Security with Google Cloud

A company lifts an on-premises workload onto Compute Engine. Under that IaaS model, where does the bulk of security responsibility sit?

With Google, apart from user account managementGoogle covers rather less than that at this layer.
With the customer, Google holding the infrastructureCorrect · your answerCorrect. Lift-and-shift buys the least coverage.
With Google for everything above the hypervisorGuest operating systems sit above it and stay yours.
Split evenly between Google and the customerThe split is never described as an even one.

Correct.

Concept

The service model decides how much of the stack you still operate. The lower the abstraction you buy, the more layers stay yours to configure and patch.

Why B

In IaaS the bulk of the security responsibilities are the customer's, and the provider responsibilities focus on the underlying infrastructure and physical security.

Source

Infrastructure as a service (IaaS) IaaS services include Compute Engine , Cloud Storage , and networking services such as Cloud VPN , Cloud Load Balancing , and Cloud DNS . IaaS provides compute, storage, and network services on demand with pay-as-you-go pricing. You can use IaaS if you plan on migrating an existing on-premises workload to the cloud using lift-and-shift, or if you want to run your application on particular VMs, using specific databases or network configurations. In IaaS, the bulk of the security responsibilities are yours, and our responsibilities are focused on the…

Google Cloud: Shared responsibilities and shared fate, checked August 2026
#gcp#shared-responsibility#iaas#security

Now you: objective 5.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

5-1Trust and Security with Google Cloud

A team moves an application onto App Engine and GKE. Under PaaS, which controls are described as shared rather than owned outright?

Sample question 2 of 3

5-1Trust and Security with Google Cloud

An analyst asks which responsibilities never move whatever service model is chosen. What always stays with the customer?

Sample question 3 of 3

5-1Trust and Security with Google Cloud

A company adopts Google Workspace for corporate email. Under the SaaS model, what does it remain responsible for?

Full Cloud Digital Leader question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Trust and Security with Google Cloud