A multinational technology company is migrating its customer analytics workloads to a managed Platform as a Service (PaaS) cloud architecture. Under this service model, the Cloud Service Provider (CSP) manages the physical hardware, hypervisors, database engine software, and underlying operating system runtime environments. The company's security engineering team must establish appropriate security architecture controls for the hosted applications and sensitive data. Under the cloud shared responsibility model, which of the following tasks remains the sole responsibility of the customer organization?
- AApplying security updates and kernel patches to the underlying database host operating systems.
- Configuring application-level access permissions, client data classification policies, and database user authorization schemas.Answer
- CMaintaining network perimeter firewall appliances surrounding the cloud provider's internal virtualized hypervisor infrastructure.
- DAuthenticating infrastructure API calls made by the cloud provider's hypervisor automated maintenance scripts.
Answer
Configuring application-level access permissions, client data classification policies, and database user authorization schemas.
Under the cloud shared responsibility model for Platform as a Service (PaaS), the cloud service provider manages the physical data center, hardware infrastructure, hypervisor, and operating system runtime environment. The tenant organization retains full ownership and responsibility for securing its application code, user authorization configurations, data classification, and stored datasets.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model in Platform as a Service (PaaS)