Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A commercial logistics enterprise is migrating its legacy cargo tracking application to an Infrastructure as a Service (IaaS) environment hosted by a public cloud service provider. During the architecture review, the chief information security officer (CISO) requests clarification on operational security boundaries under the shared responsibility model. Which of the following best describes the security responsibility allocation for this deployment?

  1. The enterprise retains responsibility for guest operating system patching and host-based firewall configurations, while the cloud provider manages physical hardware maintenance and hypervisor updates.Cevap
  2. B
    The cloud provider assumes full responsibility for operating system security updates and customer access control policies across all provisioned virtual instances.
  3. C
    The enterprise can rely entirely on the cloud provider's boundary firewalls to secure internal traffic between virtual instances without implementing workload-level access controls.
  4. D
    Deploying automated operating system patch management serves primarily as a detective control designed to identify unauthorized hypervisor modifications.

Cevap

The enterprise retains responsibility for guest operating system patching and host-based firewall configurations, while the cloud provider manages physical hardware maintenance and hypervisor updates.
In Infrastructure as a Service (IaaS), the cloud provider is responsible for securing and maintaining the underlying physical facilities, host hardware, storage subsystems, and hypervisor virtualization layer. The cloud customer remains responsible for everything running on top of the hypervisor, including guest operating system installation and patching, host firewalls, middleware, data encryption, and access management.

Adım Adım Çözüm

1
Identify the cloud service model referenced in the scenario.
The scenario specifies an Infrastructure as a Service (IaaS) deployment model.
Security boundaries shift depending on whether the service model is IaaS, PaaS, or SaaS.
2
Apply the Cloud Shared Responsibility Model to the IaaS framework.
The CSP manages physical assets, storage infrastructure, network hardware, and the hypervisor layer. The customer manages guest OS, application security, middleware, network configuration (firewalls/subnets), and identity governance.
In IaaS, virtualized hardware resources are delivered to the customer, leaving software stack maintenance to the subscriber.
3
Evaluate the options against the derived responsibility boundaries.
The option stating the enterprise manages guest OS patching while the CSP manages hypervisors accurately delineates IaaS duties.
This alignment matches CompTIA Security+ standards for cloud security architecture.

Anahtar Kavram

Shared Responsibility Model in IaaS Cloud Deployments
Bu soruyu puanla