nerdexam
IBM

C1000-176 · Question #3

In the context of the IBM Cloud shared responsibility model, what aspect of security is IBM solely responsible for in a Platform as a Service (PaaS) offering?

The correct answer is B. Physical security of data centers. In any cloud model - IaaS, PaaS, or SaaS - the cloud provider is always solely responsible for physical security of the data centers, because customers never have physical access to the underlying hardware infrastructure. In a PaaS offering, IBM manages the platform layer and…

Designing Secure Cloud Solutions

Question

In the context of the IBM Cloud shared responsibility model, what aspect of security is IBM solely responsible for in a Platform as a Service (PaaS) offering?

Options

  • AApplication code security
  • BPhysical security of data centers
  • CSecurity of customer data
  • DSecurity of client-side devices

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    79% (27)
  • C
    3% (1)
  • D
    12% (4)

Explanation

In any cloud model - IaaS, PaaS, or SaaS - the cloud provider is always solely responsible for physical security of the data centers, because customers never have physical access to the underlying hardware infrastructure. In a PaaS offering, IBM manages the platform layer and everything beneath it, including the buildings, servers, and physical access controls.

Why the distractors are wrong:

  • A (Application code security): In PaaS, customers write and deploy their own application code, making them responsible for its security.
  • C (Customer data security): Customers own and are responsible for protecting the data they store and process, regardless of cloud model.
  • D (Client-side devices): Devices used to access cloud services are entirely outside IBM's control and remain the customer's responsibility.

Memory tip: Use the phrase "IBM owns the iron." No matter what service model (IaaS, PaaS, SaaS), IBM physically controls the hardware - walls, locks, servers - and that responsibility never shifts to the customer.

Topics

#shared responsibility model#PaaS security#physical security#data center security

Community Discussion

No community discussion yet for this question.

Full C1000-176 Practice