An analyst is preparing a vulnerability report for a cloud IaaS environment. The scan shows customer-configured storage exposure, an unpatched customer VM, and a provider-side hypervisor vulnerability. The report is being shared with both the cloud provider and internal app owners. Which reporting practice best clarifies remediation ownership?
Select an answer to reveal the explanation.
Short Explanation
Think of a shared cloud like an apartment building: the landlord fixes the boiler, but you still lock your own door. Tag each finding with who owns it so nobody shrugs and says, 'Not my job.' The trap is treating everything the scanner sees as the provider's problem.
Full Explanation
Accurate vulnerability reporting in IaaS depends on shared responsibility modeling: infrastructure and platform services are provider-managed, while guest OS configuration, application code, identity, and data controls are customer-managed. Tagging each finding with the responsible party makes the report actionable because internal owners can triage customer-owned weaknesses and the provider can address provider-owned service defects without unnecessary escalation. It also prevents remediation gaps where both sides assume the other will fix a finding. A report that lists all findings together and asks the provider to fix every detected vulnerability misstates the boundary, because provider responsibility does not extend to customer VM patching, storage ACLs, or application settings. A report that includes only provider-owned issues removes customer-managed risk from the record, which defeats vulnerability management and leaves unpatched guest systems unaddressed. A report that sends raw scan output to the provider and lets them decide which findings need action shifts analytical ownership, obscures accountability, and fails to communicate the customer-side remediation plan. Exam caveat: shared responsibility changes by service model, so IaaS, PaaS, and SaaS boundaries are not identical. Operational check: add a responsible-party field to each finding, such as provider-managed, customer-managed, or shared, and verify that every customer-managed finding is assigned to an internal owner before distribution.