A financial services company uses Amazon Simple Storage Service (Amazon S3) to store sensitive customer transaction records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer responsible for performing?
- AUpgrading the operating systems and applying security patches to the physical servers hosting Amazon S3 buckets
- Configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, to restrict access to the stored transaction recordsAnswer
- CManaging the physical security of the storage media and data centers where the bucket data is replicated
- DObtaining and managing formal compliance certifications, such as SOC 2, for the underlying physical storage hardware infrastructure
Answer
Configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, to restrict access to the stored transaction records
The task of configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, represents security 'in' the cloud. Because the customer owns the data stored in the S3 bucket, they are solely responsible for determining who can access that data and configuring the permissions accordingly.
Step-by-Step Solution
Key Concept
AWS Shared Responsibility Model for Managed Services (Amazon S3)