An organization is migrating its workloads to Microsoft Azure. Match each management task to the party responsible for its execution under the Azure Shared Responsibility Model. (Each option is used once.)
- Securing the physical hardware and datacenter facilitiesSolely Microsoft
- Patching the guest operating system on an Azure Virtual MachineSolely the Customer
- Configuring identity access control and user permissionsSolely the Customer
Answer
Securing the physical hardware and datacenter facilities is solely Microsoft's responsibility. Patching the guest operating system on an Azure Virtual Machine is solely the Customer's responsibility. Configuring identity access control and user permissions is solely the Customer's responsibility.
Physical security is always managed by Microsoft because they own the physical facilities. Guest operating system patching on Azure Virtual Machines belongs solely to the customer because virtual machines are IaaS. Identity access management is a constant customer responsibility across all cloud models.
Step-by-Step Solution
Key Concept
Under the Shared Responsibility Model, physical infrastructure security is always Microsoft's responsibility, guest operating system maintenance in IaaS is the customer's responsibility, and identity access control is always the customer's responsibility.