Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A logistics enterprise is migrating its legacy inventory management platform to a cloud-hosted Infrastructure as a Service (IaaS) environment. As part of establishing the operational security baseline, the security team is defining the boundary of duties between the customer organization and the cloud service provider (CSP). Based on the cloud shared responsibility model, which of the following security tasks is the exclusive responsibility of the customer organization?

  1. Patching the guest operating system and configuring host-based firewall rules on virtual machinesCevap
  2. B
    Updating firmware and applying hypervisor security patches across physical compute hardware
  3. C
    Managing physical access controls and environmental protections for cloud datacenters
  4. D
    Configuring network routing protocols and physical switch port security within the provider core network

Cevap

Patching the guest operating system and configuring host-based firewall rules on virtual machines is the exclusive responsibility of the customer organization.
Under Infrastructure as a Service (IaaS), the cloud service provider is responsible for the 'security OF the cloud' (hardware, hypervisors, physical network, facility controls), whereas the customer is responsible for 'security IN the cloud' (guest operating system maintenance, middleware, application installation, data classification, and host firewall configuration). Therefore, patching guest operating systems and setting up host firewalls is entirely the customer's duty.

Adım Adım Çözüm

1
Identify the cloud service model referenced in the scenario.
The scenario specifies an Infrastructure as a Service (IaaS) deployment.
Different service models (IaaS, PaaS, SaaS) partition duties differently between the customer and provider.
2
Analyze the scope of responsibility assigned to the customer in IaaS.
In IaaS, the cloud provider manages hardware, facilities, network abstraction, and hypervisor software, while the customer manages OS, applications, runtime environments, and data controls.
The boundary of control starts at the guest operating system layer for the customer.
3
Evaluate each task against the IaaS responsibility boundary.
Guest OS patching and host firewall configuration fall above the hypervisor line, making them customer responsibilities.
The provider does not have access to manage or patch internal guest OS settings on tenant virtual machines.

Anahtar Kavram

Cloud Shared Responsibility Model in IaaS
Bu soruyu puanla