Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium

A company is using a public cloud provider for its entire IT infrastructure. During a recent security audit, a critical finding was identified: several virtual machines (VMs) are running vulnerable operating system versions and unpatched applications. This indicates a failure in maintaining the security posture of the compute environment. Which cloud security responsibility model aspect is primarily highlighted by this finding?

  1. ACloud Service Provider (CSP) contractual obligations.
  2. BThird-party auditor's liability.
  3. CShared Responsibility Model: Customer's Responsibility in the Cloud.
  4. DShared Responsibility Model: Cloud Provider's Responsibility for the Cloud.
Show answer & explanation

Correct answer: C. Shared Responsibility Model: Customer's Responsibility in the Cloud.

In the Shared Responsibility Model, the cloud provider is responsible for the 'security *of* the cloud' (e.g., physical infrastructure, virtualization layer), while the customer is responsible for 'security *in* the cloud' (e.g., guest operating systems, applications, configurations, data). Maintaining patched operating systems and applications on VMs falls squarely under the customer's responsibility.

Why the other options are wrong

  • A. While CSPs have contractual obligations, this finding relates to the operational security of customer-managed resources, which falls under the customer's direct responsibility, not a breach of CSP's core contract.
  • B. The auditor's liability relates to their audit process, not the operational security of the cloud environment itself.
  • D. The cloud provider is responsible for the underlying infrastructure, but not typically for patching guest operating systems or applications running within customer-provisioned VMs.

Shared Responsibility Model

A framework outlining security responsibilities between a cloud provider and its customers, differentiating between 'security of the cloud' and 'security in the cloud'.

  • CSP: 'Security OF the cloud' (physical, hypervisor).
  • Customer: 'Security IN the cloud' (OS, apps, data, config).
  • Responsibility varies by service model (IaaS, PaaS, SaaS).

Memory trick: CSP secures the cloud beneath, customer handles all within.

More Cloud Platform and Infrastructure Security questions