The document introduces 'cloud-trust,' a security assessment model for Infrastructure as a Service (IaaS) clouds that quantifies the security levels of cloud service providers (CSPs) and identifies vulnerabilities to advanced persistent threats (APTs). By evaluating four different multi-tenant IaaS architectures, it demonstrates that a minimal set of security controls results in a high probability of data compromise, while a comprehensive defense in depth approach significantly reduces this risk. The model aims to assist cloud tenants, especially government agencies, in making informed security decisions when choosing CSPs.