A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?
In an Infrastructure-as-a-Service (IaaS) model, Microsoft retains full responsibility for the physical security of the underlying data centers, including the buildings, servers, networking hardware, and environmental controls. This encompasses safeguarding against unauthorized physical access, environmental threats, and ensuring the integrity of the foundational infrastructure. This division of responsibility is a fundamental aspect of the shared responsibility model, where the cloud provider manages the "security of the cloud."
Why this answer
Under the shared responsibility model, Microsoft is responsible for the physical security of its Azure data centers, including access controls, surveillance, and environmental safeguards. The customer is responsible for securing the virtual machine's operating system, applications, and data, but not the physical infrastructure. Therefore, Microsoft retains responsibility for physical security even when the customer manages the guest OS and application.
Exam trap
The trap here is that candidates mistakenly think the customer is responsible for all security when they manage the OS and application, but physical security always remains the provider's responsibility under the shared responsibility model.
Why the other options are wrong
In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not the customer. The customer is responsible for securing their own data, applications, and configurations on the VM.
In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not shared. The customer is responsible for securing the OS, applications, and data, but not the physical infrastructure.
Physical security of the data center is always the responsibility of the cloud provider (Microsoft) under the shared responsibility model; it is never eliminated in cloud computing.