A healthcare provider deploys AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to manage employee access to clinical applications. Under the AWS Shared Responsibility Model, which two tasks are the sole responsibility of the customer? (Select TWO.)
- Creating and managing organizational units (OUs), user accounts, and group memberships within the directoryCevap
- Configuring Group Policy Objects (GPOs) to enforce security compliance on domain-joined instancesCevap
- CPatching and updating the underlying Windows operating system of the domain controllers
- DManaging the physical security and replication of domain controller hardware across Availability Zones
- EDownloading compliance documents from AWS Artifact to automatically audit and verify internal directory user permissions
Cevap
Creating and managing organizational units (OUs), user accounts, and group memberships within the directory, as well as configuring Group Policy Objects (GPOs) to enforce security compliance on domain-joined instances, are the responsibility of the customer.
Under the AWS Shared Responsibility Model for managed services, AWS manages the host environment, operating system patching, and domain controller hardware availability. The customer retains full control over the logical administration of the directory, which includes managing directory objects (users, groups, organizational units) and configuring policies (such as GPOs) for domain-joined resources.
Adım Adım Çözüm
Anahtar Kavram
For managed services like AWS Managed Microsoft AD, AWS handles host deployment, patching, physical security, and replication of domain controllers, while the customer is responsible for directory administrative tasks, user and group management, and policy configurations.