A biotechnology firm is deploying a proprietary genomic data processing application on virtual machines hosted within an Infrastructure as a Service (IaaS) cloud environment. Which of the following maintenance and security tasks remain the direct responsibility of the firm's internal IT administration team? (Select TWO.)
- Applying security patches to the guest operating systems and installed application stacksAnswer
- Configuring host-based firewall rules and OS-level network security controlsAnswer
- CUpdating and patching the underlying bare-metal Type 1 hypervisor software
- DReplacing defective physical hard drives in the cloud provider's storage arrays
Answer
The customer's internal IT administration team is responsible for applying security patches to guest operating systems and application stacks, as well as configuring host-based firewall rules and OS-level network access security controls.
Under the cloud shared responsibility model for Infrastructure as a Service (IaaS), the cloud provider manages the physical infrastructure, facility security, physical host servers, storage arrays, and hypervisor layer. The customer retains operational responsibility for everything built on top of the virtual hardware, which includes installing and patching guest operating systems, managing application middleware, configuring guest network settings, and enforcing host-based firewall rules.
Step-by-Step Solution
Key Concept
Shared Responsibility Model in IaaS (Customer OS/App Control vs. Provider Infrastructure Control)