IaaS vs PaaS vs SaaS: Cloud Models Made Simple
Cloud service models are the rare topic that shows up on all three CompTIA exams we teach. IaaS, PaaS, and SaaS are tested on A+ Core 1, Network+, and Security+, each from a slightly different seat. Learn it once, draw it the right way, and it pays off across every track. This guide keeps it plain: what the three models mean, who manages what in each, the analogy that finally makes it stick, and exactly where each exam puts it.
What do IaaS, PaaS, and SaaS actually mean?
They are three ways to rent computing, sorted by how much the provider runs for you. IaaS rents raw infrastructure. PaaS rents a ready platform. SaaS rents finished software.
Every cloud service sits on a stack: physical hardware, networking, storage, the virtualization layer, the operating system, the runtime and middleware, then the application and your data on top. On-premises means you own and maintain that entire ladder in your own building. Each service model hands a different number of those rungs to the provider. The definitions here are not marketing terms. They come straight from NIST SP 800-145, the reference CompTIA and most of the industry lean on.
Here is the short version of each:
The pattern is a sliding scale, not three separate worlds. As you move from IaaS to SaaS, the provider takes more of the stack and you take less.
- IaaS (Infrastructure as a Service): the provider runs the hardware, network, and virtualization. You get virtual machines, storage, and networks, then install the operating system and everything above it. Most control, most upkeep.
- PaaS (Platform as a Service): the provider also manages the operating system and runtime. You deploy your application and manage your data. Less control, far less maintenance.
- SaaS (Software as a Service): the provider runs the whole stack. You open a finished app in a browser and manage your accounts and your data. Least control, least upkeep.
Who manages what? The line moves with every model
The provider takes over more of the stack as you move from IaaS to SaaS, but you never hand off everything. In every model you still own your data, your user accounts, and how the service is configured.
This split has a name: the shared responsibility model. Cloud providers describe their half as security of the cloud, meaning the buildings, servers, and core services, and your half as security in the cloud, meaning your data, access, and settings. As the abstraction rises, the provider handles more of the operational security, but data governance and identity never leave your side.
Broken down by model, the customer's job looks like this:
Notice the constant: configuration and data are always yours. That is why most cloud incidents are not dramatic break-ins. They are settings left open by accident. Security+ leans on this idea hard, which is the whole reason it tests the responsibility line rather than trivia.
- IaaS: you manage the operating system, patches, applications, and data. The provider handles the hardware and virtualization underneath.
- PaaS: you manage your applications and data. The provider handles the operating system and runtime.
- SaaS: you manage your users, permissions, and data. The provider handles nearly everything else.
The pizza analogy works if you draw the line in the right place
Think about dinner. On-premises is cooking from scratch at home. IaaS is take-and-bake. PaaS is delivery. SaaS is dining out. The higher you go, the less you handle and the less you control.
Cooking at home, you buy every ingredient, own the oven, and clean up. That is on-premises: total control, total work. Take-and-bake hands you a prepared pizza, but you supply the oven and the heat. That is IaaS, where the provider gives you the raw ingredients and you run the environment.
Delivery brings a finished pizza to your door. You still supply the table, the drinks, and the dining room. That is PaaS: the platform is handled, and you bring the app and the data. Dining out means the restaurant does everything, and you just show up and eat. That is SaaS.
The analogy only works if you remember one thing: at every level, you are still the one eating, and you still chose what to order. Your data and your decisions never get outsourced. That is the same line the shared responsibility model draws, dressed up as dinner.
Public, private, hybrid, community: the four deployment models
Service models answer how much is managed for you. Deployment models answer who else shares the hardware. NIST names four: public, private, hybrid, and community.
These stack on top of the service models. You can run SaaS in a public cloud or a private one. A+ Core 1 expects all four deployment models by name, while Network+ leans on public, private, and hybrid as the common trio. Keep the two axes separate in your head: one is about management, the other is about tenancy.
- Public cloud: shared infrastructure that many organizations use over the internet. Cost-efficient and scalable, with the least direct control over the hardware.
- Private cloud: infrastructure dedicated to one organization, whether hosted internally or by a provider. More control and isolation, higher cost.
- Community cloud: shared by several organizations with common needs, such as agencies bound by the same compliance rules.
- Hybrid cloud: a mix of public and private, with data and applications moving between them to balance cost, control, and demand.
This is on 220-1201, N10-009, and SY0-701: one topic, three lenses
The same three models are tested three ways. A+ asks you to summarize them. Network+ asks how you connect to them. Security+ asks who secures what. One concept, three exams, three angles.
This is the part most study material skips, and it is exactly where we anchor everything. A help-desk simulator that never maps a concept to an exam objective leaves you guessing whether what you just practiced is even on the test. We map every topic to the domain that tests it, so the same asset earns its place across all three tracks.
Here is the breakdown, domain by domain:
Study it once with the responsibility line clear, and you have answered a chunk of three exams. If you want the security angle in more depth, our Zero Trust walkthrough builds on the same architecture domain.
- A+ Core 1 (220-1201): the Virtualization and Cloud Computing domain, about 11 percent of the exam. Objective 4.2, Summarize cloud computing concepts, covers the three service models and all four deployment models. The A+ angle is recognition: know the definitions cold.
- Network+ (N10-009): the Networking Concepts domain, about 23 percent of the exam. Its cloud concepts and connectivity options objective, 1.3, folds in NFV, VPCs, gateways, and how you actually reach these services. The Network+ angle is connectivity.
- Security+ (SY0-701): the Security Architecture domain, about 18 percent of the exam. Objective 3.1 puts the shared responsibility model front and center. The Security+ angle is accountability: who secures what, and where the customer's job begins.
How do you know you actually know this yet?
Recognizing IaaS in a sentence is not the same as answering a question that hides the label. The honest signal is whether you can place the responsibility line under pressure, not whether the term looks familiar.
This is where we point you at the Mastery Index. It is an internal study signal built from your quiz and practice-exam answers, shown with an evidence-quality label so you know how much it is based on. It is not calibrated against the real exam, and it does not predict a pass. It is an honest read of whether you actually know a topic yet, which is a different and more useful thing than a score that flatters you.
Then make it stick with the hands-on layer. Study mode drills the definitions with flashcards, quizzes, and PBQs. Adventure and the Help Desk Simulator drop you into ticket scenarios where the difference between IaaS and SaaS decides who you escalate to and what you are allowed to touch. That is the same call you will make in week one on a real desk.
One honest note: if you have never opened a cloud console, do not start in the simulator. Start with the concept and the analogy here, get the responsibility line solid, then go practice. The order matters.
Learn the line once, and three exams get lighter
Here is the whole thing in one breath. Service models sort by how much the provider runs, from IaaS up to SaaS. You always keep your data, your accounts, and your configuration. Deployment models are a separate question about who shares the hardware. And the same idea is tested three ways across A+, Network+, and Security+. Get the responsibility line clear, pressure-test it with the Mastery Index, and put it to work in a ticket scenario. No cert hands you a job, and nothing here guarantees a pass. But this is one of the few topics that pays you back on three exams and on your first week doing the work.
Sources
- NIST. The NIST Definition of Cloud Computing (SP 800-145). Authoritative source for the three service models (IaaS, PaaS, SaaS) and four deployment models (public, private, hybrid, community).
- CompTIA. CompTIA A+ Core 1 (220-1201) certification and exam objectives. Virtualization and Cloud Computing domain; download the objectives PDF to confirm the objective numbers and domain weighting.
- CompTIA. CompTIA Network+ (N10-009) certification and exam objectives. Networking Concepts domain covers cloud concepts and connectivity options, including service and deployment models.
- Amazon Web Services. AWS Shared Responsibility Model. Major-vendor reference for security of the cloud vs security in the cloud, and how the split shifts by service abstraction.
Who writes this, and who checks it

Nick writes and edits these posts. AI helps with research, outlines, and first drafts. Nick reviews the draft before it goes live, and he is the only reviewer, so this is one person checking his own work. That catches a lot and it misses some.
When a post turns out to be wrong, the fix and the date it happened go on the corrections log, in public, including the ones nobody outside noticed. We do not use confidential, recalled, or leaked exam content. These posts are written from CompTIA's published objectives and authoritative technical sources. The AI policy has the longer version.
LinkedIn ↗