During a cloud credential theft incident, your SOC confirms an identity compromise in an IaaS tenant and sees telemetry suggesting the provider-managed hypervisor may be involved. The shared-responsibility agreement requires prompt notification when provider controls are implicated. Which incident communication requirement applies?
Select an answer to reveal the explanation.
Short Explanation
Think of shared responsibility like renting an apartment: you lock your door, but the landlord owns the building wiring. If smoke is coming from the walls, you don't wait to finish your own inspection before calling the landlord. You notify the cloud provider or MSP as soon as the shared boundary is involved.
Full Explanation
Shared-responsibility models divide security duties between the customer and the provider or managed service partner. The customer typically owns identities, data, workloads, and network configuration inside the tenant, while the provider owns the underlying infrastructure, hypervisor, physical security, and managed service components. When incident evidence suggests that provider-managed controls may be affected, the SOC must notify the external party promptly because that party has the visibility, authority, and contractual obligation to investigate or remediate its side. Internal-only escalation is incomplete when the suspected impact crosses the shared boundary, even if legal, communications, or business owners are already engaged. Waiting for forensic certainty can breach notification clauses and delays containment, because early notice allows the provider to preserve provider-side logs and coordinate response. Notifying only the data owner addresses business impact and data stewardship but does not give the provider the information needed to act on infrastructure or managed-service risk. Exam caveat: do not assume every cloud incident stays inside the SOC; read the shared-responsibility and contract terms. Operational check: verify the provider or MSP notification contact, severity thresholds, and log-preservation request path before the next incident.