Open cardosec

Case 0405C7 · Cloud · L1 Foundations

Shared Responsibility Model

Practise as: Explain it · Interview

Interview questionExplain the shared responsibility model and give an example where teams get it wrong.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. The provider secures the cloud (hardware, hypervisor, facilities); the customer secures what they put in it
  2. The split shifts by service: IaaS leaves OS patching to you; SaaS leaves mostly identity, data and configuration
  3. Customer always owns identity, access policy, data classification and configuration
  4. Classic failure: assuming the provider encrypts or backs up everything, or that a bucket cannot be made public by mistake
  5. Map it explicitly per service in your control framework so ownership gaps are visible

If the interviewer pushes back

  • Where does responsibility sit for a managed Kubernetes control plane versus its worker nodes?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.