Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A maritime shipping enterprise is formalizing its cloud security architecture strategy across diverse operational environments. Match each security operational requirement on the left with the corresponding cloud model or security architecture component on the right.

  • Enforcing data loss prevention (DLP) and access controls across web applications used by corporate employees without modifying the cloud application code.Cloud Access Security Broker (CASB)
  • Provisioning isolated compute and storage infrastructure exclusively dedicated to single-tenant regulatory compliance data within an enterprise-controlled datacenter.Private Cloud Deployment Model
  • Deploying virtual instances where the enterprise retains full administrative control over operating system hardening, middleware configuration, and local firewall rules.Infrastructure as a Service (IaaS)
  • Participating in a joint logistics tracking platform hosted in the cloud and shared exclusively among authorized trade partners and customs authorities.Community Cloud Deployment Model

Cevap

Enforcing DLP across web applications matches Cloud Access Security Broker (CASB); Dedicated single-tenant infrastructure matches Private Cloud Deployment Model; Managing guest OS hardening and firewall rules on virtual instances matches Infrastructure as a Service (IaaS); Shared tracking platform among authorized partners matches Community Cloud Deployment Model.
Each operational requirement correctly aligns with its architectural counterpart based on the shared responsibility model and deployment boundaries: CASB handles proxy/API security enforcement for cloud applications, Private Cloud guarantees single-tenant isolation, IaaS gives the customer full OS-level management control, and Community Cloud supports shared infrastructure restricted to specified industry partners.

Adım Adım Çözüm

1
Analyze the operational security requirement for intermediate policy enforcement over third-party web apps.
Identify that a Cloud Access Security Broker (CASB) provides inline or API-based enforcement of DLP and access control across cloud services.
CASB acts as an intermediary enforcing security, compliance, and governance policies.
2
Evaluate the tenancy and location requirements for single-tenant compliance data.
Map single-tenant, dedicated enterprise infrastructure to a Private Cloud model.
Private clouds guarantee isolated resources managed solely for one enterprise.
3
Examine the management responsibility boundary of guest OS hardening and middleware.
Map guest OS administration and virtual firewall control to Infrastructure as a Service (IaaS).
In IaaS, the customer retains control over the operating system and above, while the provider manages physical infrastructure.
4
Determine the cloud deployment model for infrastructure shared among bounded organizations with common goals.
Map joint industry partner platforms to a Community Cloud model.
Community clouds host joint infrastructure shared exclusively among participating entities with shared missions or compliance mandates.

Anahtar Kavram

Cloud Service and Deployment Models
Tahmini Süre:1m 30s
Bu soruyu puanla