Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A smart utility metering company is migrating its real-time telemetry processing pipeline to a public cloud environment. The architecture utilizes cloud-hosted virtual machines (IaaS) for running custom protocol ingestion agents and a fully managed database service (PaaS) for long-term data warehousing. Which TWO of the following operational security tasks remain the direct responsibility of the utility company's security team across both service models?

  1. Configuring role-based access controls and identity permissions for database objects and virtual machinesCevap
  2. Encrypting customer metering data at rest and managing the cryptographic key rotation policiesCevap
  3. C
    Applying security patches to the underlying physical hypervisors and storage controller firmware
  4. D
    Inspecting network ingress traffic at the physical cloud datacenter perimeter firewalls

Cevap

The utility company remains directly responsible for configuring role-based access controls and identity permissions, as well as encrypting customer metering data at rest and managing key rotation policies.
Under the cloud Shared Responsibility Model, data security (including data encryption at rest and managing encryption keys) and identity governance (configuring user access permissions and role-based policies) are strictly customer responsibilities regardless of whether IaaS, PaaS, or SaaS is utilized. The cloud service provider manages lower-level physical infrastructure and platform components, but tenant data configuration and access rights are always managed by the customer.

Adım Adım Çözüm

1
Analyze the cloud deployment components and service models in the scenario.
The infrastructure uses Infrastructure as a Service (IaaS) for virtual machine ingestion agents and Platform as a Service (PaaS) for the managed data warehouse.
Identifying the service models establishes the division of duties under the Shared Responsibility Model.
2
Evaluate candidate security tasks against customer vs. Cloud Service Provider (CSP) responsibility boundaries.
The CSP manages physical facilities, hypervisors, server hardware, and database engine infrastructure. The customer retains control and responsibility over identity/access management (IAM), data security, data classification, and encryption configuration across both service types.
Under the cloud shared responsibility model, ownership of data and access control configurations always resides with the customer tenant.

Anahtar Kavram

Shared Responsibility Model across IaaS and PaaS deployment models
Bu soruyu puanla