A logistics company migrates its core inventory database to a public cloud Infrastructure as a Service (IaaS) environment using custom virtual machine instances. Under the cloud shared responsibility model, which of the following tasks is the sole operational security responsibility of the customer enterprise?
- Applying operating system security updates and configuring host-based firewalls on virtual machinesAnswer
- BUpgrading hypervisor software versions and replacing failing physical disk arrays in storage racks
- CConfiguring network perimeter firewalls to grant implicit trust to all internal subnet traffic
- DExecuting user identity authentication protocols when assigning object file access permissions
Answer
Applying operating system security updates and configuring host-based firewalls on virtual machines is the sole operational security responsibility of the customer enterprise.
In Infrastructure as a Service (IaaS), the cloud provider is responsible for securing the underlying physical infrastructure, virtualization hypervisors, and data center facilities. The customer enterprise retains total administrative responsibility for everything running above the hypervisor layer, including installing, patching, and hardening guest operating systems, as well as managing host-based network controls.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model (IaaS)