Question 1 of 30
AstroDynamics, a space exploration firm, utilizes Infrastructure as a Service (IaaS) from NebulaCloud, a prominent cloud service provider. AstroDynamics has deployed a proprietary mission control application onto a virtual machine instance managed by NebulaCloud. Security analysts discover a critical flaw in the application\'s data encryption module, leading to the potential exposure of sensitive orbital trajectory data. This flaw was introduced during the application\'s development phase by AstroDynamics\' internal software engineering team. According to the principles outlined in ISO 27017:2015, which entity bears the primary responsibility for addressing this identified vulnerability within the application\'s code?
AstroDynamics, as the vulnerability resides within their custom-developed application code and its implementation within the cloud environment.
NebulaCloud, due to their overarching responsibility for the security of the cloud infrastructure, which includes all deployed applications.
Both AstroDynamics and NebulaCloud share equal responsibility, necessitating a joint remediation effort for any cloud-based security issue.
The responsibility shifts to NebulaCloud if the vulnerability could be exploited through the network interfaces managed by NebulaCloud, regardless of the application's origin.

Preparing for ISO 27017:2015 Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free