A global logistics organization migrates its freight tracking platform to a cloud provider's managed container orchestration service (PaaS). Under the contract, the cloud service provider maintains the physical host infrastructure, hypervisor layer, and control plane nodes. To maintain regulatory compliance, the organization's security architect must establish the operational control boundaries for the deployment. Which of the following security responsibilities rests exclusively with the organization in this managed cloud model?
- Configuring container workload security policies, application data encryption keys, and pod access boundaries.Cevap
- BApplying firmware updates and kernel patches to the physical hypervisors running the managed control plane.
- CRelying on private cloud subnets to implicitly trust all internal inter-container network traffic without verification.
- DTreating user identity authentication verification as an automatic approval for cluster authorization permissions.
Cevap
Configuring container workload security policies, application data encryption keys, and pod access boundaries.
In PaaS and managed container orchestration environments, the cloud service provider abstracts and manages the underlying hardware, hypervisors, and control plane. The customer retains full ownership and responsibility for application-level security, container workload policies, access control rules, and key management for data encryption.
Adım Adım Çözüm
Anahtar Kavram
Shared Responsibility Model in Platform as a Service (PaaS)
Tahmini Süre:2m 0s