正解:D
TheShared Responsibility Modelin cloud computing establishes that:
* Cloud providersare responsible for securing the underlyinginfrastructure, networking, and hardware.
* Customers (organizations)are responsible for securingdata, identity and access management (IAM), encryption, and complianceobligations.
* Data ownershipremainswith the customer, even though visibility into cloud infrastructure may be limited.
The major security challenge in cloud computing is thatorganizations lack full control over cloud infrastructurebut must still ensure that security policies align withregulatory requirements (e.g., GDPR, HIPAA, PCI DSS).
This principle is outlined in:
* CCSK v5 - Security Guidance v4.0, Domain 2 (Governance and Enterprise Risk Management)
* Cloud Security Alliance's (CSA) Cloud Controls Matrix (CCM) - Data Security and Governance.