Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A financial technology organization is deploying a multi-tier payment processing service using a managed Platform as a Service (PaaS) database solution provided by a cloud vendor. Under the cloud shared responsibility model, which of the following security tasks remains the exclusive responsibility of the organization's engineering team?

  1. Configuring database user access policies and managing data classification and encryption controlsCevap
  2. B
    Applying security patches and update packages to the underlying host operating system running the database service
  3. C
    Establishing physical security controls and perimeter network isolation around the cloud provider's hardware infrastructure
  4. D
    Treating user identity authentication verification as a replacement for defining row-level data query authorization privileges

Cevap

Configuring database user access policies and managing data classification and encryption controls is the customer's responsibility in a PaaS deployment.
Under the cloud shared responsibility model for Platform as a Service (PaaS), the cloud service provider manages the physical hardware, network infrastructure, hypervisor, operating system, and database engine maintenance. The customer remains responsible for securing its data, configuring access permissions, implementing data classification, and enforcing appropriate data-at-rest encryption settings.

Adım Adım Çözüm

1
Identify the cloud service model referenced in the scenario.
The deployment utilizes Platform as a Service (PaaS).
The responsibility division between the customer and provider depends directly on whether the service model is IaaS, PaaS, or SaaS.
2
Analyze the division of responsibility for PaaS deployments.
The Cloud Service Provider manages the hardware, network infrastructure, hypervisor, host OS, and database engine maintenance, while the customer manages data schemas, user permissions, and application configuration.
PaaS abstracts lower-level infrastructure management away from the customer.
3
Evaluate the options against customer responsibilities.
Managing data classification, database user access controls, and encryption configuration remains entirely with the customer.
The customer always owns and retains security responsibility for its data across all cloud service models.

Anahtar Kavram

Cloud Shared Responsibility Model in PaaS
Bu soruyu puanla