Microsoft Azure環境における設定ミスによる侵害に関するフォレンジック調査において、調査担当者は、クライアント組織がユーザーID、エンドポイントデバイス、およびデータを管理し、Microsoftが物理ホスト、ネットワーク、およびデータセンターの運用を担当していることを確認しました。このような責任分担を最もよく表しているクラウドサービスモデルはどれでしょうか?
正解:C
The correct answer is C because the responsibility split described in the question aligns most closely with Infrastructure as a Service. Microsoft's Azure shared responsibility documentation explains that responsibilities differ depending on whether the service model is SaaS, PaaS, or IaaS. In IaaS, the provider is responsible for the physical datacenter, physical hosts, networking fabric, and core infrastructure, while the customer remains responsible for significant portions of what runs in the environment, including identities, endpoints, data, operating systems, and workload configuration. That matches the scenario much more closely than SaaS, where Microsoft would handle substantially more of the stack. On-premises deployment would place nearly all responsibility on the organization itself, which also does not fit. CHFI v11 includes cloud computing service models, cloud threats, and cloud forensics, so candidates are expected to connect a forensic scenario to the correct service model by examining who manages which layers. Since Microsoft handles the physical cloud infrastructure while the customer manages core usage-side components and data, the best answer is Infrastructure as a Service.