An enterprise organization is migrating a mission-critical web service to a public cloud Infrastructure as a Service (IaaS) environment utilizing customer-managed virtual machines behind a cloud provider's network load balancer. Under the cloud Shared Responsibility Model, which of the following security functions remain the explicit responsibility of the enterprise security team? (Select TWO.)
- Configuring guest operating system security patches and host-based firewall policies on the deployed virtual machines.Answer
- Defining application data access controls and configuring customer-managed encryption for data stored within cloud volumes.Answer
- CManaging physical hardware maintenance and applying hypervisor security updates across the underlying cloud host infrastructure.
- DTrusting all internal network traffic between virtual machines without continuous authentication once cloud edge security groups are established.
Answer
The enterprise security team is responsible for configuring guest operating system patches and host firewalls, as well as managing application data access controls and storage volume encryption.
Under Infrastructure as a Service (IaaS), the cloud service provider manages the underlying physical facilities, hardware, and hypervisor abstraction layer. The customer retains explicit responsibility for configuring, patching, and securing everything above the hypervisor layer, including guest operating systems, host-based firewalls, identity permissions, and data encryption.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model in Infrastructure as a Service (IaaS)