A university is expanding its online video streaming platform by establishing a hybrid cloud architecture. The IT security team deploys virtual machines within a public cloud Infrastructure as a Service (IaaS) tenant to handle high-throughput video transcoding workloads, while maintaining student academic records within an on-premises datacenter. Which of the following operational security responsibilities fall solely on the university's internal security team for the public cloud IaaS components? (Select TWO.)
- Configuring guest operating system network firewalls and installing OS-level security patchesAnswer
- Defining access control policies and identity permissions for video data storage buckets and application usersAnswer
- CApplying firmware updates to physical hypervisor hosts and maintaining datacenter facility security
- DAutomatically trusting all incoming network traffic originating from the internal private network without continuous verification
Answer
The university's internal security team is solely responsible for configuring guest operating system firewalls and applying OS patches, as well as managing access control policies for application data and identity permissions.
In Infrastructure as a Service (IaaS), the cloud provider manages the physical infrastructure, facility security, hardware, and hypervisor layer. The customer retains full responsibility for managing the guest operating systems (including OS firewall rules and patch management) and defining access control and identity permissions for data assets stored within the cloud environment.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model in IaaS Environments