CV0-003 · Question #13
In an IaaS model, to which of the following methodologies would the client apply a list of OS patches, assuming approval from CAB has been given?
The correct answer is A. Using a patch management system, identify the hypervisor type, select a group of hypervisors to. In an IaaS model, the client owns OS-level patching of guest VMs and must first identify the hypervisor type to confirm patch compatibility before selecting target systems for deployment.
Question
In an IaaS model, to which of the following methodologies would the client apply a list of OS patches, assuming approval from CAB has been given?
Options
- AUsing a patch management system, identify the hypervisor type, select a group of hypervisors to
- BUsing a patch management system, identify the guests that require patching, and select and
- CUsing a patch management system, identify the applications needing the patch, select the
- DUsing a patch management system, identify the services that require patching, and select and
How the community answered
(27 responses)- A74% (20)
- B4% (1)
- C15% (4)
- D7% (2)
Why each option
In an IaaS model, the client owns OS-level patching of guest VMs and must first identify the hypervisor type to confirm patch compatibility before selecting target systems for deployment.
In an IaaS environment, the client uses a patch management system to identify the underlying hypervisor type first, which determines guest OS patch compatibility and any virtualization-specific constraints before selecting the target group of VMs. After CAB approval, this methodology ensures OS patches are applied in a controlled, compatibility-verified manner that respects the client-managed layers of the IaaS shared responsibility model.
Identifying only the guest VMs without first identifying the hypervisor type skips the compatibility verification step that ensures OS patches are appropriate for the specific virtualization environment in use.
Identifying applications needing a patch describes application-level patching, not OS-level patching, which is a distinct maintenance scope within the IaaS client responsibility model.
Identifying services for patching rather than the hypervisor type and target guest group does not follow the correct OS patch management methodology for an IaaS environment.
Concept tested: IaaS OS patch management process and client responsibility
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
Topics
Community Discussion
No community discussion yet for this question.