Soru

Zorluk: Çok zorCloud Architecture and Deployment Models

A pharmaceutical research firm integrates an on-premises high-performance compute cluster with a cloud-managed Platform as a Service (PaaS) database pipeline to process sensitive genomic records across a hybrid cloud model. To protect data in transit and control unauthorized access, the security team implements an inline Cloud Access Security Broker (CASB) alongside microsegmentation. When evaluating security responsibility boundaries under this PaaS architecture, which security management task remains exclusively the responsibility of the cloud customer?

  1. Managing customer-managed encryption keys (CMEK) and defining database user privilege policiesCevap
  2. B
    Applying security patches to the hypervisor and underlying operating system running the database cluster
  3. C
    Classifying queries originating from the internal corporate network as inherently trusted without enforcing continuous authorization
  4. D
    Applying physical lock controls and video surveillance inside the cloud provider data center facilities

Cevap

Managing customer-managed encryption keys (CMEK) and defining database user privilege policies is exclusively the customer's responsibility in a PaaS model.
Under the cloud shared responsibility model for Platform as a Service (PaaS), the cloud service provider abstract and manages the underlying hardware, hypervisors, and database engine software. However, data ownership, access control configurations, user entitlement definitions, and data-at-rest encryption key lifecycle management (such as CMEK) always remain under the explicit administrative control of the cloud customer.

Adım Adım Çözüm

1
Identify the cloud service model referenced in the scenario.
The scenario explicitly specifies a Platform as a Service (PaaS) database pipeline deployment.
Shared responsibility boundaries vary significantly between IaaS, PaaS, and SaaS models.
2
Analyze the scope of Cloud Service Provider (CSP) responsibilities in PaaS.
The CSP manages physical facility security, hypervisor infrastructure, host OS patching, database runtime software, and physical hardware maintenance.
PaaS abstracts the underlying infrastructure and operating system from the customer.
3
Analyze the customer's responsibilities in PaaS.
The customer retains full ownership and responsibility for data classification, application data access policies, database user account privileges, and customer-managed encryption keys (CMEK).
Regardless of cloud model, data ownership and access governance remain entirely under customer control.

Anahtar Kavram

Cloud Shared Responsibility Model in Platform as a Service (PaaS)
Bu soruyu puanla