A financial organization is migrating an existing legacy internal application to a public Infrastructure as a Service (IaaS) environment. Under the cloud shared responsibility model, which of the following security management tasks are the direct responsibility of the organization? (Select TWO.)
- Patching operating system vulnerabilities on deployed virtual instancesAnswer
- Configuring network access rules and host-based firewalls on virtual serversAnswer
- CUpdating hypervisor firmware across physical host hardware servers
- DMaintaining physical access security and environmental controls for the cloud data center
Answer
The organization is responsible for patching operating system vulnerabilities on deployed virtual instances and configuring network access rules and host-based firewalls on virtual servers.
In an Infrastructure as a Service (IaaS) cloud architecture, the cloud service provider (CSP) takes responsibility for securing physical data centers, host hardware, and hypervisors. The customer assumes responsibility for securing the guest operating systems (including applying OS patches) and managing access traffic through virtual firewall configurations and host-based security rules.
Step-by-Step Solution
Key Concept
Shared Responsibility Model in IaaS Cloud Architecture
Estimated Time:1m 30s