Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A university is expanding its online video streaming platform by establishing a hybrid cloud architecture. The IT security team deploys virtual machines within a public cloud Infrastructure as a Service (IaaS) tenant to handle high-throughput video transcoding workloads, while maintaining student academic records within an on-premises datacenter. Which of the following operational security responsibilities fall solely on the university's internal security team for the public cloud IaaS components? (Select TWO.)

  1. Configuring guest operating system network firewalls and installing OS-level security patchesCevap
  2. Defining access control policies and identity permissions for video data storage buckets and application usersCevap
  3. C
    Applying firmware updates to physical hypervisor hosts and maintaining datacenter facility security
  4. D
    Automatically trusting all incoming network traffic originating from the internal private network without continuous verification

Cevap

The university's internal security team is solely responsible for configuring guest operating system firewalls and applying OS patches, as well as managing access control policies for application data and identity permissions.
In Infrastructure as a Service (IaaS), the cloud provider manages the physical infrastructure, facility security, hardware, and hypervisor layer. The customer retains full responsibility for managing the guest operating systems (including OS firewall rules and patch management) and defining access control and identity permissions for data assets stored within the cloud environment.

Adım Adım Çözüm

1
Analyze the cloud service model referenced in the scenario.
The infrastructure uses Infrastructure as a Service (IaaS).
Determining the service model establishes the baseline division of duties in the Shared Responsibility Model.
2
Delineate customer responsibilities from cloud service provider (CSP) responsibilities in IaaS.
The CSP manages physical facility security, host hardware, and the hypervisor layer. The customer manages guest OS, middleware, runtime applications, network security controls on the VM, and data access policies.
IaaS leaves all operating system management and data protection under the customer's operational scope.
3
Identify the two options matching the customer's operational scope.
Guest OS firewalling/patching and data/identity access control policy configuration are customer duties.
These activities align directly with customer-owned layers in IaaS architecture.

Anahtar Kavram

Cloud Shared Responsibility Model in IaaS Environments
Bu soruyu puanla