nerdexam
CSA

CCSK · Question #230

Which of the following are the primary security responsibilities of the cloud provider in compute virtualization? (Select 2)

The correct answer is A. Isolation D. Securing the underlying infrastructure. In the cloud shared responsibility model for compute virtualization, the provider is responsible for isolating customer workloads from each other and securing the underlying physical and hypervisor infrastructure.

Virtualization and Containers

Question

Which of the following are the primary security responsibilities of the cloud provider in compute virtualization? (Select 2)

Options

  • AIsolation
  • BIdentity & Access Management
  • CEncryption
  • DSecuring the underlying infrastructure
  • EMonitoring and Logging

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    14% (4)
  • C
    3% (1)
  • E
    7% (2)

Why each option

In the cloud shared responsibility model for compute virtualization, the provider is responsible for isolating customer workloads from each other and securing the underlying physical and hypervisor infrastructure.

AIsolationCorrect

Isolation is a core provider responsibility because only the cloud provider controls the hypervisor and can enforce that one tenant's VMs cannot access another's memory or CPU. Securing the underlying infrastructure (D) means the provider must protect physical hardware, firmware, hypervisor software, and network fabric from compromise, as customers have no visibility or control over these layers.

BIdentity & Access Management

Identity and Access Management for workloads and applications is a customer responsibility - the provider supplies IAM tooling but the customer configures and governs access to their own resources.

CEncryption

Encryption of data in transit and at rest for customer workloads is a customer responsibility, though the provider may offer encryption services that the customer must choose to enable and configure.

DSecuring the underlying infrastructureCorrect

Securing the underlying infrastructure is an explicit provider duty under all major cloud shared responsibility frameworks, covering data center physical security, host OS patching, and hypervisor integrity.

EMonitoring and Logging

Monitoring and logging of application-level activity and security events within the customer's environment is the customer's responsibility, even though providers offer tools to facilitate it.

Concept tested: Cloud shared responsibility model in compute virtualization

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility

Topics

#compute virtualization#provider responsibilities#isolation#shared responsibility

Community Discussion

No community discussion yet for this question.

Full CCSK Practice