Question

Difficulty: MediumShared Responsibility Model

An organization is migrating several workloads to Microsoft Azure. To ensure proper operational governance, the IT team must define responsibility boundaries. Match each operational task to its correct responsibility assignment under the Azure Shared Responsibility Model.

  • Classifying and protecting intellectual property and data stored in Microsoft 365Customer's sole responsibility
  • Configuring network firewall rules and access controls for an Azure App Service web appShared responsibility between the customer and Microsoft
  • Maintaining and securing physical hypervisor hosts and datacenters in an Azure regionMicrosoft's sole responsibility

Answer

Data classification in Microsoft 365 matches Customer's sole responsibility; Network firewall configuration in Azure App Service matches Shared responsibility; Physical host maintenance matches Microsoft's sole responsibility.
The correct pairings map the tasks as follows: Data classification and governance for Microsoft 365 is a customer-only responsibility because the customer always owns their data. Configuring network controls for Azure App Service is a shared responsibility because both parties play a role in network security configuration. Maintaining the physical hypervisors and datacenters is a Microsoft-only responsibility as the customer has no physical access to Azure's hardware.

Step-by-Step Solution

1
Analyze the service model for each task.
Microsoft 365 is Software as a Service (SaaS), Azure App Service is Platform as a Service (PaaS), and physical infrastructure applies across all models.
Identifying the cloud service model is the first step to applying the Shared Responsibility Model rules.
2
Determine ownership for physical security.
Physical infrastructure security is always Microsoft's responsibility.
Microsoft manages the physical facilities and hardware, meaning the customer has no access to or responsibility for physical security.
3
Determine ownership for data security in SaaS.
Information and data governance is always the customer's responsibility.
Even in SaaS, the customer owns their data and must classify and control access to it.
4
Determine ownership for network controls in PaaS.
Network controls in PaaS represent a shared responsibility.
Microsoft manages the network infrastructure, but the customer is responsible for configuring access rules and firewalls.

Key Concept

Shared Responsibility Model
Estimated Time:1m 30s
Rate this question