Soru

Zorluk: ZorCloud Architecture and Deployment Models

A global logistics organization migrates its freight tracking platform to a cloud provider's managed container orchestration service (PaaS). Under the contract, the cloud service provider maintains the physical host infrastructure, hypervisor layer, and control plane nodes. To maintain regulatory compliance, the organization's security architect must establish the operational control boundaries for the deployment. Which of the following security responsibilities rests exclusively with the organization in this managed cloud model?

  1. Configuring container workload security policies, application data encryption keys, and pod access boundaries.Cevap
  2. B
    Applying firmware updates and kernel patches to the physical hypervisors running the managed control plane.
  3. C
    Relying on private cloud subnets to implicitly trust all internal inter-container network traffic without verification.
  4. D
    Treating user identity authentication verification as an automatic approval for cluster authorization permissions.

Cevap

Configuring container workload security policies, application data encryption keys, and pod access boundaries.
In PaaS and managed container orchestration environments, the cloud service provider abstracts and manages the underlying hardware, hypervisors, and control plane. The customer retains full ownership and responsibility for application-level security, container workload policies, access control rules, and key management for data encryption.

Adım Adım Çözüm

1
Analyze the cloud service model presented in the scenario.
The scenario describes a managed container service (PaaS) where the cloud service provider (CSP) manages the physical infrastructure, hypervisor, and control plane.
Determining the service model establishes the baseline division of duties under the Shared Responsibility Model.
2
Differentiate CSP responsibilities from customer responsibilities.
The CSP manages host security, physical facilities, and control plane uptime. The customer retains ownership of data classification, container configuration, runtime security, and access rules.
Customers operating in PaaS retain full control over data and application-level security.
3
Identify the option that correctly reflects exclusive customer responsibility.
Managing container security configurations, pod access controls, and application encryption keys is strictly a customer duty.
Application layer controls and customer-managed keys cannot be managed by the CSP.

Anahtar Kavram

Shared Responsibility Model in Platform as a Service (PaaS)
Tahmini Süre:2m 0s
Bu soruyu puanla