Soru

Zorluk: OrtaCloud Architecture and Deployment Models

An enterprise security architect is reviewing the security boundaries for a newly deployed application utilizing Function as a Service (FaaS) within a public cloud provider. To ensure governance and compliance, the security team must establish clear operational boundaries under the cloud shared responsibility model. Which of the following management tasks remains the primary responsibility of the customer in this serverless architecture deployment?

  1. Configuring application identity access management, input validation, and data encryption policiesCevap
  2. B
    Patching vulnerabilities within the underlying server operating system and container runtime
  3. C
    Establishing perimeter firewall boundaries to implicitly trust internal function-to-function communications
  4. D
    Managing hypervisor isolation security and physical hardware provisioning in the cloud data center

Cevap

Configuring application identity access management, input validation, and data encryption policies
Under the cloud shared responsibility model for serverless (Function as a Service) deployments, the cloud provider abstracts away physical hardware, hypervisors, operating systems, and runtime execution environments. Consequently, customer responsibility shifts up the stack to focus strictly on securing application source code, implementing robust identity and access controls, sanitizing inputs, and enforcing data encryption policies.

Adım Adım Çözüm

1
Analyze the cloud deployment model and service type specified in the scenario.
The deployment is Function as a Service (FaaS / Serverless) in a public cloud environment.
Understanding the service model determines the division of duties in the shared responsibility model.
2
Differentiate Cloud Service Provider (CSP) responsibilities from customer responsibilities for serverless computing.
The CSP manages physical infrastructure, network infrastructure, host hypervisors, runtime environments, and OS patching. The customer manages application logic, code security, data classification, and access permissions.
Higher-level cloud abstractions shift hardware and OS management to the CSP while keeping application-layer control with the customer.
3
Select the option that aligns with the customer's retained duties.
Managing application access management, input validation, and data encryption policies resides with the customer.
Customers are always responsible for securing their data and application code regardless of cloud abstraction level.

Anahtar Kavram

Cloud Shared Responsibility Model for Serverless Architectures
Bu soruyu puanla