Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A biotechnology company is deploying a cloud-native genomic analysis pipeline utilizing a Function-as-a-Service (FaaS) model coupled with managed cloud object storage. The lead security architect is formalizing operational boundaries to comply with the cloud shared responsibility model. Which of the following tasks remains exclusively the responsibility of the biotechnology company?

  1. Hardening application source code, managing data classification, and configuring API access authorization rules.Cevap
  2. B
    Applying security patches and operating system updates to the underlying container execution nodes and serverless runtimes.
  3. C
    Implicitly trusting all serverless execution calls originating from internal corporate IP addresses without continuous access verification.
  4. D
    Utilizing user identity authentication to automatically satisfy all application data permissions without configuring separate authorization rules.

Cevap

Hardening application source code, managing data classification, and configuring API access authorization rules.
In Function-as-a-Service (FaaS) serverless architectures, the cloud service provider abstracts away physical hardware, virtualization, and runtime environment management. However, the tenant retains full ownership and responsibility for customer data classification, application source code security, and identity and access governance (including API authorization).

Adım Adım Çözüm

1
Identify the cloud service model being evaluated.
The scenario specifies Function-as-a-Service (FaaS), a serverless compute model.
Different service models (IaaS, PaaS, SaaS, FaaS) shift different infrastructure management responsibilities between the customer and provider.
2
Determine the cloud service provider's operational scope under FaaS.
The CSP manages physical infrastructure, server hardware, OS patching, runtime environment maintenance, and container orchestration.
Serverless models abstract the underlying server infrastructure away from the enterprise.
3
Determine the customer's operational scope under FaaS.
The customer is responsible for writing secure code, configuring API endpoints, enforcing IAM policies, securing data at rest and in transit, and setting access authorization controls.
Regardless of how high up the stack the cloud model moves, data security and application security remain customer responsibilities.

Anahtar Kavram

Shared Responsibility Model in Function-as-a-Service (FaaS)
Bu soruyu puanla