ISO 27017:2015 - Cloud Security Lead Implementer Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A multinational corporation, \'Aether Dynamics\', has migrated its critical financial applications to a cloud environment utilizing an Infrastructure as a Service (IaaS) model. The company\'s Chief Information Security Officer (CISO) is reviewing the shared responsibility matrix with the chosen Cloud Service Provider (CSP). Aether Dynamics\' internal audit team has identified a critical zero-day vulnerability in the widely used operating system deployed on their virtual servers, which has not yet been patched by the OS vendor. Considering the principles outlined in ISO 27017:2015 for cloud security responsibilities, which party bears the primary accountability for mitigating this specific operating system-level vulnerability within the IaaS context?

Aether Dynamics, as the customer is responsible for securing the operating system and applications deployed within the IaaS environment.
The Cloud Service Provider, due to their overarching responsibility for the security of the cloud infrastructure.
The operating system vendor, as they are the creators of the vulnerable software.
A joint responsibility, with the CSP providing a secure platform and Aether Dynamics managing the OS patching.

About the ISO 27017:2015 - Cloud Security Lead Implementer Certification

These free practice questions are designed to help you assess your readiness for the ISO 27017:2015 - Cloud Security Lead Implementer exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.