Aster Logistics processes confidential shipping data on an IaaS deployment in a public cloud. Its internal audit team is scoping an audit of the environment and must decide what falls within the audit boundary given the shared responsibility model. Which element is properly INSIDE the scope of Aster's own audit?
- AThe physical security of the cloud provider's data centre facilities
- BThe patching of the underlying hypervisor running the tenant's virtual machines
- CThe configuration of guest operating systems and security groups the tenant manages Correct
- DThe provider's internal staff vetting and background-check procedures
Why A is wrong: Physical facility security is the provider's responsibility under IaaS and is covered by the provider's own attestations, so it sits outside the customer's audit boundary.
Why B is wrong: The hypervisor is maintained by the provider in any cloud service model, so the tenant cannot audit or control its patching and it lies outside the customer scope.
Why C is correct: Under IaaS the customer manages the guest OS, network security groups and application layer, so these tenant-controlled configurations are squarely within Aster's own audit scope.
Why D is wrong: Provider personnel screening is part of the provider's control set assessed through its own audits, not something the customer includes in its audit scope.