A financial technology company deploys a transactional database using Amazon Relational Database Service (Amazon RDS). As part of a security audit, the company must document the division of operational tasks based on the AWS Shared Responsibility Model. Which of the following tasks is the customer's responsibility under the AWS Shared Responsibility Model for this database deployment?
- AApplying security patches and updates to the guest operating system hosting the database engine
- BManaging the physical security and environmental controls of the storage servers containing the database volumes
- Configuring database-level user access controls and network access rules via database security groupsAnswer
- DGenerating third-party compliance certification reports, such as SOC 2, for the AWS data center physical infrastructure
Answer
Configuring database-level user access controls and network access rules via database security groups
Configuring network access rules using database security groups and managing database-level user access are customer responsibilities (security 'in' the cloud). Even under a managed database service like Amazon RDS, the customer must configure who can access the database resources.
Step-by-Step Solution
Key Concept
AWS Shared Responsibility Model for Managed Services