C1000-176 · Question #83
In the IBM Cloud shared responsibility model, who is responsible for the security of the operating system in an Infrastructure as a Service (IaaS) offering?
The correct answer is B. The customer. In IaaS, IBM Cloud manages the physical infrastructure (servers, networking, data centers), but the customer takes full responsibility for everything above the hypervisor - including the operating system, its patching, hardening, and configuration. This is the defining…
Question
In the IBM Cloud shared responsibility model, who is responsible for the security of the operating system in an Infrastructure as a Service (IaaS) offering?
Options
- AIBM Cloud
- BThe customer
- CBoth IBM Cloud and the customer
- DThird-party service providers
How the community answered
(27 responses)- A7% (2)
- B78% (21)
- C11% (3)
- D4% (1)
Explanation
In IaaS, IBM Cloud manages the physical infrastructure (servers, networking, data centers), but the customer takes full responsibility for everything above the hypervisor - including the operating system, its patching, hardening, and configuration. This is the defining characteristic of IaaS: you get raw compute, and you own the software stack on top of it.
Why the distractors are wrong:
- A (IBM Cloud): IBM only owns the OS in Platform as a Service (PaaS) or Software as a Service (SaaS) offerings, where they manage the runtime environment.
- C (Both): Shared OS responsibility applies in PaaS, not IaaS - in IaaS, the split is clean: IBM owns below the OS, you own the OS and above.
- D (Third-party providers): Third parties are not part of the IBM Cloud shared responsibility model by default; they have no defined role in OS security here.
Memory tip: Use the acronym "IaaS = I am Solely responsible" - the customer handles the OS and everything above it, while IBM handles everything below (hardware, virtualization, network fabric).
Topics
Community Discussion
No community discussion yet for this question.