Soru

Zorluk: OrtaShared Responsibility Model

An organization is migrating its workloads to Azure and wants to align its security operations with the Microsoft Azure Shared Responsibility Model. Match each administrative responsibility to its correct ownership profile under the cloud service models.

  • Securing the physical infrastructure, hosts, and network cabling in the Azure datacenter.A responsibility that is always managed by Microsoft, regardless of the cloud service model deployed.
  • Applying security patches and updates to the operating system of a web server running on an Azure Virtual Machine.A responsibility that shifts to the customer specifically under the Infrastructure as a Service (IaaS) model.
  • Defining information protection policies and classifying sensitive corporate documents stored in Microsoft 365.A responsibility that always remains with the customer, regardless of the cloud service model deployed.

Cevap

Physical infrastructure security is always Microsoft's responsibility; operating system patching on Azure Virtual Machines shifts to the customer in IaaS; and data classification and governance always remain with the customer in all cloud models.
The matches align with the Shared Responsibility Model: physical security is always Microsoft's responsibility across all models; guest OS patching is the customer's responsibility in IaaS; and data governance is always the customer's responsibility in all models.

Adım Adım Çözüm

1
Identify the ownership boundary for physical security.
Physical infrastructure is always maintained by Microsoft across all service models (IaaS, PaaS, SaaS).
The customer has no physical access to the cloud datacenters, so Microsoft manages all physical security.
2
Determine who is responsible for operating system maintenance in Infrastructure as a Service (IaaS).
The customer is responsible for guest operating system configuration, updates, and patching.
In IaaS, Microsoft only provides the hypervisor and host; the guest OS is managed by the customer.
3
Determine who is responsible for document and data governance in Software as a Service (SaaS).
The customer is always responsible for the security of their data, information, and identity.
In all cloud models, including SaaS (e.g., Microsoft 365), data classification and access management remain the customer's responsibility.

Anahtar Kavram

Shared Responsibility Model
Bu soruyu puanla