medium
Single Answer
0In an infrastructure-as-a-service environment where a vendor supplies a customer with access to storage services, who is normally responsible for removing sensitive data from drives that are taken out of service?
Answer Options
A
Customer's security team
B
Customer's storage team
C
Customer's vendor management team
D
Vendor
Correct Answer: D
Explanation
In an infrastructure-as-a-service environment, security duties follow a shared responsibility model. Since the vendor is responsible for managing the storage hardware, the vendor would retain responsibility for destroying or wiping drives as they are taken out of service. However, it is still the customer's responsibility to validate that the vendor's sanitization procedures meet their requirements prior to utilizing the vendor's storage services.