Which component is secured by the cloud provider in a shared responsibility model?
In the cloud shared responsibility model, the provider is responsible for securing the underlying infrastructure that delivers the cloud service. This includes physical data centers, facilities, power, cooling, physical networking, storage hardware, and host servers that support customer workloads. Therefore, the host server is the correct answer. A customer is generally responsible for securing what they configure or deploy in the cloud, such as virtual machines, operating systems, applications, identities, and data, depending on the service model. Website authentication is an application or identity-layer responsibility and usually belongs to the customer or application owner. On-premises connectivity to hosts is also customer-controlled because it involves the organization's network design, VPN, routing, and access policies. The exact boundary shifts across SaaS, PaaS, and IaaS, but the provider consistently secures the cloud infrastructure itself. Palo Alto Networks explicitly includes the cloud shared responsibility model as a Cloud Security objective for Apprentice candidates. Reference: Cybersecurity Apprentice Datasheet, Cloud Security 5.3.
Currently there are no comments in this discussion, be the first to comment!