A fleet logistics company transitions its core routing engine to an Infrastructure as a Service (IaaS) environment provided by a public cloud vendor. The IT team deploys multiple virtual machines to host the application software. Which of the following operational security responsibilities remains exclusively with the logistics company?
- Configuring guest operating system firewall rules and applying system patches to the virtual machinesCevap
- BUpdating physical hypervisor firmware and maintaining underlying host hardware infrastructure
- CAssigning system permissions automatically by mistaking network access location for validated user identity
- DAssuming internal network traffic originating within the cloud subnet requires no microsegmentation or continuous verification
Cevap
Configuring guest operating system firewall rules and applying system patches to the virtual machines
Under the Cloud Shared Responsibility Model for Infrastructure as a Service (IaaS), the cloud service provider manages the physical infrastructure, storage hardware, physical data center security, and the hypervisor layer. The subscriber retains full administrative control and operational responsibility for the guest operating systems, including patching, local host firewall configurations, installed software packages, and data governance.
Adım Adım Çözüm
Anahtar Kavram
Cloud Shared Responsibility Model in IaaS Deployments