An enterprise security team is implementing a Platform as a Service (PaaS) managed container environment to host web microservices. Under the shared responsibility model, the Cloud Service Provider (CSP) maintains the underlying hardware, hypervisors, and orchestrator control plane. Which of the following operational tasks remains the primary responsibility of the enterprise security team?
- Configuring application-level access controls and remediating vulnerabilities in custom container image code.Answer
- BApplying firmware updates and OS security patches to the physical server nodes hosting the cluster.
- CImplicitly trusting all inter-service network traffic routing within the private virtual cloud subnet.
- DUtilizing authentication protocols to specify granular data modification permissions for authenticated users.
Answer
Configuring application-level access controls and remediating vulnerabilities in custom container image code is the primary responsibility of the customer enterprise.
Under the cloud shared responsibility model for Platform as a Service (PaaS), the cloud service provider manages the physical infrastructure, network layer, hypervisor, and container orchestrator engine. The customer remains responsible for application code security, data classification, and access control configuration.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model in PaaS Environments
Estimated Time:1m 30s