Question 1 of 30
Consider a scenario where a cloud service customer (CSC) is utilizing a Platform as a Service (PaaS) offering from a cloud service provider (CSP). A security audit reveals that sensitive customer data stored within the PaaS application has been inadvertently exposed due to overly permissive access controls configured within the CSC\'s application deployment. According to the principles outlined in ISO 27017:2015, which party bears the primary responsibility for rectifying this specific security lapse?
The cloud service customer, for misconfiguring the access controls within their deployed application.
The cloud service provider, for failing to enforce stricter default access control policies on the PaaS platform.
Both the cloud service provider and the cloud service customer, sharing equal responsibility for the misconfiguration.
A joint incident response team comprising representatives from both the cloud service provider and the cloud service customer, to determine the root cause.

Preparing for ISO 27017:2015 - Cloud Security Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free