Free Palo Alto Networks Cybersecurity-Apprentice Actual Exam Questions - Question 7 Discussion

Question No. 7
A medium-sized organization migrates its workloads to a public cloud provider. The IT manager is
unsure about which security responsibilities remain with the organization and which are handled by the
cloud provider. The manager seeks to clarify their responsibilities under the shared responsibility model.
Under the shared responsibility model in a public cloud environment, which of the following is the
organization's responsibility?
Select all that apply, then reveal solution.
US
RS
Ravi S.
2026-01-28

D imo, since configuring firewalls is about securing the workloads they run, which the org controls directly. The provider handles the hardware and data center security, but the org needs to set up network protections like firewalls for their VMs. Managing user identities (C) is important too, but sometimes identity management tools are provided by the cloud service itself, so firewall config feels more clearly on the org side here.

0
RS
Ravi S.
2026-01-26

This one’s about what the org controls directly. Since A and B are clearly provider’s job, it’s between C and D. Organizations always manage their user accounts and access rights, so I’d say C.

0
ZN
Zain N.
2026-01-25

C/D? Managing identities (C) is definitely on the org since they control users, but configuring firewalls (D) is also usually the org’s job to protect their VMs. Both make sense depending on context.

0
ZN
Zain N.
2026-01-22

C managing user identities is definitely on the org since they control who gets access; cloud providers don’t manage that part. Firewall setup might be more variable depending on the service level.

0
OV
Omar V.
2026-01-22

It’s D because the cloud provider takes care of the physical infrastructure and data center security, so A and B are definitely off the table. Between C and D, managing user access is part of identity management, but firewall configuration directly controls the security of the organization's own virtual machines, which they have to handle themselves. So D fits better since it’s about securing their workloads specifically.

0
AX
Ahmed X.
2026-01-15

D imo, since the org usually handles firewall configs for their VMs, while hardware and physical security are on the cloud provider. Identity stuff feels more like a shared thing but mainly on the org side.

0