CompTIA Security+ (SY0-701)Security ArchitectureEasy
A company migrates its web application to a public cloud provider using Infrastructure as a Service (IaaS). Under the shared responsibility model, which of the following security tasks remains the customer's responsibility?
- APatching the underlying hypervisor firmware
- BPhysical security of the data center housing the hypervisor
- CMaintaining redundant power and cooling for host hardware
- DConfiguring security groups and patching the guest operating system
Show answer & explanationAnswer & explanation
Correct answer: D. Configuring security groups and patching the guest operating system
In IaaS, the cloud provider secures the physical infrastructure, hypervisor, and facility, while the customer is responsible for securing everything they control, including the guest OS, applications, and network configurations such as security groups.
Why the other options are wrong
- A. Hypervisor management and patching belongs to the cloud provider.
- B. Physical data center security is always the provider's responsibility in cloud models.
- C. Facility power and cooling are provider-managed infrastructure concerns.
Shared Responsibility Model
A cloud security framework defining which security tasks belong to the cloud provider versus the customer, varying by service model (IaaS, PaaS, SaaS).
- IaaS: provider secures hardware/hypervisor; customer secures OS, apps, data.
- SaaS: provider secures almost everything except data and access management.
- Misunderstanding this model is a leading cause of cloud misconfigurations.
Memory trick: Provider builds the house, customer locks the doors.