A financial technology organization is deploying a multi-tier payment processing service using a managed Platform as a Service (PaaS) database solution provided by a cloud vendor. Under the cloud shared responsibility model, which of the following security tasks remains the exclusive responsibility of the organization's engineering team?
- Configuring database user access policies and managing data classification and encryption controlsCevap
- BApplying security patches and update packages to the underlying host operating system running the database service
- CEstablishing physical security controls and perimeter network isolation around the cloud provider's hardware infrastructure
- DTreating user identity authentication verification as a replacement for defining row-level data query authorization privileges
Cevap
Configuring database user access policies and managing data classification and encryption controls is the customer's responsibility in a PaaS deployment.
Under the cloud shared responsibility model for Platform as a Service (PaaS), the cloud service provider manages the physical hardware, network infrastructure, hypervisor, operating system, and database engine maintenance. The customer remains responsible for securing its data, configuring access permissions, implementing data classification, and enforcing appropriate data-at-rest encryption settings.
Adım Adım Çözüm
Anahtar Kavram
Cloud Shared Responsibility Model in PaaS