A company is migrating its relational database to Amazon RDS (Relational Database Service) to reduce operational overhead. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
- Configuring database-level user access and permissionsAnswer
- BInstalling operating system security patches on the database server
- Enabling encryption at rest for the database instancesAnswer
- DReplacing failed physical storage drives in the AWS data center hosting the database
- EPerforming underlying virtualization hypervisor updates
Answer
Configuring database-level user access and permissions AND Enabling encryption at rest for the database instances
Under the AWS Shared Responsibility Model for Amazon RDS, the customer is responsible for security 'in' the cloud. This includes configuring database-level user access and permissions to control access to the data, and enabling data encryption features (such as encryption at rest). AWS, on the other hand, is responsible for security 'of' the cloud, which includes managing the underlying physical infrastructure, virtualization layer, and OS-level patching.
Step-by-Step Solution
Key Concept
Shared Responsibility Model for Managed Services (PaaS)
Estimated Time:1m 0s