AZ-900 · Cloud foundations and economics
17 cards
Cloud Computing and Shared Responsibility
-
Quick check
A retail team must add compute capacity for a launch three weeks away. Why can cloud computing meet that deadline when its own datacenter cannot?
ABecause a cloud subscription ships extra servers to the team's datacenter
Cloud services arrive over the internet; nothing is shipped, and buying servers is the slow path the team is trying to avoid.
BBecause seasonal traffic is served from the team's existing on-site hardware
The existing on-site hardware is exactly the constraint here, and physical capacity cannot be built in three weeks.
CBecause services delivered over the internet are not tied to building physical capacity
Right. Internet delivery removes the wait to build another datacenter, so the organization can expand its IT footprint rapidly.
3 / 17
-
Quick check
What separates an on-premises datacenter from a cloud service in terms of responsibility?
AThe provider keeps the physical hosts and the physical network underneath the running workloads
A provider owning the hosts and the physical network describes cloud computing; on-premises, the organization owns those layers itself.
BThe organization keeps the whole stack, hardware through patching
Right. On-site operation leaves physical space, security, servers, infrastructure, software, patching and versions with the organization's own team.
CThe two parties split the duties, and the split depends on the service type bought
A division that varies with the service type is the cloud shared-responsibility model, not the everything-is-yours on-premises model.
6 / 17
-
Quick check
A security review asks which items stay with your team no matter which cloud service you buy. Which answer is correct?
AYour information and data, the devices you connect, and your accounts and identities
Right. Information and data, the devices allowed to connect, and the accounts and identities never transfer to the provider.
BThe physical network and the physical hosts underneath your workloads
The physical network and hosts are permanently the provider's, because the consumer is not collocated with the datacenter.
CThe datacenter's power and cooling, plus its physical security
Power, cooling and physical security belong to the provider for the same reason: the consumer does not operate the facility.
9 / 17
-
Keep your progress in the app
That’s 3 of 6 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
An organization wants the provider to carry as much of the service as possible while it still owns its data and identities. Which service type fits?
AIaaS, which leaves the consumer holding the largest share of the work
IaaS is the consumer-heavy end of the spectrum, which is the opposite of what this organization is asking for.
BSaaS, where the cloud provider carries most of the work
Right. SaaS places most responsibility on the provider, and data, accounts and identities stay with the consumer in any case.
CPaaS, which sits in the middle and splits the duties between the two parties
PaaS is the middle ground, so it does divide the work, but it is not the most provider-heavy option available.
12 / 17
-
Quick check
One team uses a managed cloud SQL database; another installs SQL on a virtual machine. How do the duties differ?
AThe managed database is patched by the provider, and on the virtual machine that work is yours
Right. The provider maintains the managed database, installing your own on a virtual machine makes its patches and updates yours, and the data is yours either way.
BBoth databases are patched by the provider, and in both cases the stored data becomes theirs
Installing the database yourself makes its patches and updates your job, and stored data never becomes the provider's responsibility.
CBoth databases are patched by your own team, and in both cases the provider owns the ingested data
A managed cloud database is maintained by the provider, and data ingested into either database remains the consumer's responsibility.
15 / 17
-
Quick check
Which summary of the shared responsibility model is correct?
AThe provider owns the facility and all of your data, and the service type then decides who holds identities
Data never belongs to the provider, and identities are one of the items that stay with the consumer under every service type.
BYou own the facility and your data, and the service type decides who holds the physical network
The physical facility and its network are always the provider's, so neither of them is something the service type decides.
CThe provider owns the facility, you own data, devices and identities, the service type does the rest
Right. Physical datacenter, network and hosts are the provider's, data, devices and identities are yours, and the middle layers move with the service type.
17 / 17
-
6 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.