A game development studio migrates its multiplayer matchmaking microservices to a managed Platform as a Service (PaaS) environment hosted by a public cloud provider. As part of defining the organization's cloud security baseline, the architecture team evaluates operational governance duties. Which of the following security responsibilities remains strictly with the game development studio under this cloud service model?
- Configuring application-level identity access management policies and user authentication controlsAnswer
- BPatching the underlying operating system kernels and managed runtime engine binaries
- CMaintaining physical access controls and environmental systems for the hosting data centers
- DAssuming internal platform virtual network traffic is implicitly trusted without enforcing endpoint verification
Answer
Configuring application-level identity access management policies and user authentication controls remains the customer's sole responsibility under Platform as a Service (PaaS).
Under the Platform as a Service (PaaS) shared responsibility model, the cloud provider assumes responsibility for host hardware, physical facility security, hypervisor management, operating system updates, and middleware engine maintenance. The cloud customer remains responsible for application code development, customer data management, and configuring application-level authentication and access control policies.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model (PaaS)