Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A company is utilizing a PaaS offering to host its application. The PaaS provider manages the operating system, runtime, and middleware. The company's security team is responsible for securing the application code and data. According to the shared responsibility model, what is the primary security concern for the company in this scenario?
- APhysical security of the data centers
- BNetwork infrastructure configuration
- CHypervisor and virtualization layer security
- DApplication code vulnerabilities and data encryption
Show answer & explanationAnswer & explanation
Correct answer: D. Application code vulnerabilities and data encryption
In a PaaS model, the customer is primarily responsible for securing their application code, configurations, and the data they put into the platform, including encryption, as the provider handles the underlying infrastructure.
Why the other options are wrong
- A. Physical security is the cloud provider's responsibility in PaaS.
- B. Network infrastructure configuration is largely managed by the provider in PaaS.
- C. Hypervisor security is the cloud provider's responsibility in PaaS.
Shared Responsibility Model (PaaS)
In Platform as a Service (PaaS), the cloud provider manages the underlying infrastructure and platform, while the customer is responsible for their application and data.
- Provider handles OS, runtime, middleware, virtualization, physical infrastructure.
- Customer handles application code, application configuration, data, identity/access management.
- Different from IaaS (more customer responsibility) and SaaS (more provider responsibility).
Memory trick: PaaS: Provider handles the platform, you handle your app's code and secrets.