Moving a system to the cloud changes who operates parts of the environment, but it does not remove your security responsibilities. Identify which controls the provider manages and which your team must configure.
Cloud security on SY0-701
Cloud security is more explicit on SY0-701 than on previous versions. Security Architecture (18%) and Security Operations (28%) both include cloud-relevant content. Key concepts include shared responsibility models, identity-centered access controls in cloud environments, misconfigured storage buckets, CASB (Cloud Access Security Broker), secure APIs, and the risk that automation can propagate misconfigurations rapidly.
Shared responsibility model
In IaaS, the cloud provider secures the physical infrastructure; the customer secures the operating system and everything above it. In SaaS, the provider handles most security; the customer is responsible for data governance and access control. Security+ tests whether candidates understand what each party is responsible for in each service model.