A retail company is migrating a legacy web application to Amazon Elastic Compute Cloud (Amazon EC2) instances. Under the AWS Shared Responsibility Model, which TWO of the following security tasks are the responsibility of the customer?
- Patching the guest operating system installed on the EC2 instancesAnswer
- BMaintaining the physical security of the data centers hosting the EC2 instances
- Configuring the security group rules to control traffic to the EC2 instancesAnswer
- DPatching the underlying virtualization hypervisors that run the EC2 instances
- EDecommissioning and physically destroying retired storage device hardware
Answer
The customer is responsible for patching the guest operating system and configuring the security group rules.
Under the AWS Shared Responsibility Model, customers are responsible for security 'in' the cloud. For Amazon EC2 (an Infrastructure as a Service model), this includes managing the guest operating system (such as patching and updates) and configuring security group rules to control network traffic to and from the instances.
Step-by-Step Solution
Key Concept
Shared Responsibility Model for IaaS
Estimated Time:1m 0s