An enterprise digital publishing company is migrating its core subscription portal and web application servers to an Infrastructure as a Service (IaaS) environment hosted by a public cloud provider. Under the cloud shared responsibility model, which of the following security operations remains the sole responsibility of the enterprise security team?
- Configuring guest operating system patches and host-based firewalls on deployed virtual machinesAnswer
- BUpdating hypervisor firmware and maintaining physical server rack security inside the data center
- CReplacing failed physical storage arrays and sanitizing decommissioned disk drives
- DEstablishing physical perimeter access controls and environmental cooling for server facilities
Answer
Configuring guest operating system patches and host-based firewalls on deployed virtual machines is the responsibility of the enterprise security team.
In Infrastructure as a Service (IaaS), the cloud service provider abstracts and manages the physical data center, hardware, network infrastructure, and virtualization layer (hypervisor). The customer retains operational control over the virtual machine instances, including installing, patching, and configuring guest operating systems, middleware, applications, network security rules, and host-based firewalls.
Step-by-Step Solution
Key Concept
Shared Responsibility Model in Infrastructure as a Service (IaaS)