Soru

Zorluk: OrtaCloud Architecture and Deployment Models

A bio-pharmaceutical research laboratory is deploying an automated, event-driven genomic data processing pipeline using a serverless Function-as-a-Service (FaaS) model hosted on a public cloud platform. In this architecture, cloud functions are automatically invoked whenever new dataset files are uploaded to cloud storage buckets. Under the cloud shared responsibility model, which TWO of the following security tasks are the explicit responsibility of the customer organization?

  1. Defining least-privilege Identity and Access Management (IAM) execution roles and validating input parameters within the serverless function code.Cevap
  2. B
    Applying operating system security patches and kernel updates to the container host instances executing the serverless runtime.
  3. Configuring access control policies and client-side or server-side encryption settings for raw data objects stored in cloud storage buckets.Cevap
  4. D
    Establishing a single perimeter network firewall to implicitly trust all internal API calls originating within the cloud environment.

Cevap

The two correct customer security responsibilities are: defining least-privilege IAM execution roles and input validation in function code, and configuring access control policies and encryption for data stored in cloud storage buckets.
Under the cloud shared responsibility model for serverless/FaaS environments, the customer retains accountability for their application code logic, including input validation and assigning least-privilege IAM execution roles. Additionally, data security—comprising access policies and data encryption for stored object datasets—is always managed by the customer.

Adım Adım Çözüm

1
Analyze the cloud service model presented in the scenario.
The scenario describes a serverless Function-as-a-Service (FaaS) model combined with cloud object storage.
Understanding the abstraction layer determines which components are managed by the cloud service provider versus the customer.
2
Differentiate provider responsibilities from customer responsibilities in FaaS.
The Cloud Service Provider (CSP) abstracts and secures the physical hardware, hypervisor, container OS, and serverless runtime execution environment.
The customer is relieved of server host OS maintenance and hardware provisioning duties.
3
Identify customer-owned security layers.
The customer retains full accountability for application source code, execution role permissions, data payload validation, data classification, and storage bucket encryption/access policies.
Data security and identity governance always remain customer responsibilities regardless of the cloud model.

Anahtar Kavram

Cloud Shared Responsibility Model in FaaS/Serverless Architectures
Bu soruyu puanla