Soru

Zorluk: OrtaShared Responsibility Model

A healthcare provider deploys AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to manage employee access to clinical applications. Under the AWS Shared Responsibility Model, which two tasks are the sole responsibility of the customer? (Select TWO.)

  1. Creating and managing organizational units (OUs), user accounts, and group memberships within the directoryCevap
  2. Configuring Group Policy Objects (GPOs) to enforce security compliance on domain-joined instancesCevap
  3. C
    Patching and updating the underlying Windows operating system of the domain controllers
  4. D
    Managing the physical security and replication of domain controller hardware across Availability Zones
  5. E
    Downloading compliance documents from AWS Artifact to automatically audit and verify internal directory user permissions

Cevap

Creating and managing organizational units (OUs), user accounts, and group memberships within the directory, as well as configuring Group Policy Objects (GPOs) to enforce security compliance on domain-joined instances, are the responsibility of the customer.
Under the AWS Shared Responsibility Model for managed services, AWS manages the host environment, operating system patching, and domain controller hardware availability. The customer retains full control over the logical administration of the directory, which includes managing directory objects (users, groups, organizational units) and configuring policies (such as GPOs) for domain-joined resources.

Adım Adım Çözüm

1
Analyze the service model in use.
AWS Managed Microsoft AD is a managed directory service.
Managed services shift infrastructure and platform maintenance duties (like OS patching and hardware replication) to AWS, leaving data and access configuration duties to the customer.
2
Evaluate operational actions against the Shared Responsibility Model boundary.
Administrative actions inside the directory (managing users, groups, and GPOs) belong to the customer, while maintenance of domain controller servers belongs to AWS.
AWS secures the infrastructure running the service (security 'of' the cloud), while the customer secures the data and configurations put into the service (security 'in' the cloud).

Anahtar Kavram

For managed services like AWS Managed Microsoft AD, AWS handles host deployment, patching, physical security, and replication of domain controllers, while the customer is responsible for directory administrative tasks, user and group management, and policy configurations.
Bu soruyu puanla