Case 0405C7 · Cloud · L1 Foundations
Shared Responsibility Model
Practise as: Explain it · Interview
Interview questionExplain the shared responsibility model and give an example where teams get it wrong.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- The provider secures the cloud (hardware, hypervisor, facilities); the customer secures what they put in it
- The split shifts by service: IaaS leaves OS patching to you; SaaS leaves mostly identity, data and configuration
- Customer always owns identity, access policy, data classification and configuration
- Classic failure: assuming the provider encrypts or backs up everything, or that a bucket cannot be made public by mistake
- Map it explicitly per service in your control framework so ownership gaps are visible
If the interviewer pushes back
- Where does responsibility sit for a managed Kubernetes control plane versus its worker nodes?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.