An analyst is investigating lateral movement from an IaaS workload in a hybrid SOC. The team needs telemetry it can control under the shared responsibility model. Which source is customer-owned for that workload?
Select an answer to reveal the explanation.
Short Explanation
Think of IaaS like renting an apartment: you control what's inside your unit, not the building's wiring. Your EDR on the OS gives you process and file logs, while hypervisor or provider switch data sits with the provider. Don't chase telemetry you don't own.
Full Explanation
In an IaaS model, the customer controls the guest operating system, applications, and most security tooling installed there, while the provider retains control of the hypervisor, physical network, and underlying compute fabric. Customer-controlled telemetry therefore comes from sources the analyst can install, configure, and log locally, such as EDR agents, OS event logs, application logs, and customer-managed cloud network logs when enabled. Provider platform telemetry may be useful for escalation, but it is not directly collectable as SOC-owned evidence unless exposed through provider APIs and contracts. Hypervisor memory introspection is provider platform telemetry because the hypervisor mediates guest memory and is not accessible from the customer VM. Physical switch port mirror captures are also provider-controlled infrastructure data, not something the customer can enable on the provider's physical network. Host bus adapter performance counters are low-level hardware or virtualization metrics generally owned by the provider, not application-level workload telemetry. Exam caveat: shared responsibility changes by service model; IaaS gives the customer guest control, while SaaS shifts much more telemetry to the provider. Operational check: confirm the EDR agent is installed, reporting, and writing process and file events from the workload OS before requesting provider-side telemetry.