Soru

Zorluk: OrtaData Protection and Encryption

A financial technology company is deploying a payment processing application on AWS. Their security policy mandates that all transaction logs must be encrypted at rest using cryptographic keys where the customer maintains direct control over key access policies. Furthermore, all data transmitted between their application servers and the database must be encrypted. Which of the following actions are responsibilities of the customer under the AWS Shared Responsibility Model to satisfy these requirements? (Select TWO.)

  1. Configuring SSL/TLS certificates on the database and enabling secure transport protocols for data in transitCevap
  2. Creating and managing key policies to control user permissions for customer managed keys in AWS Key Management Service (AWS KMS)Cevap
  3. C
    Managing the physical security and hardware lifecycle of the hardware security modules (HSMs) that store AWS KMS keys
  4. D
    Performing physical decommissioning and destruction of retired storage media containing the encrypted transaction logs
  5. E
    Deploying AWS CloudHSM to automatically manage the rotation of default AWS managed keys for AWS services

Cevap

The correct responsibilities of the customer are configuring SSL/TLS certificates on the database and enabling secure transport protocols for data in transit, and creating and managing key policies to control user permissions for customer managed keys in AWS Key Management Service (AWS KMS).
Under the AWS Shared Responsibility Model, the customer is responsible for data protection parameters they configure within the cloud. This includes configuring secure communication protocols (like SSL/TLS) for data in transit and managing access controls (such as key policies) for customer managed keys at rest.

Adım Adım Çözüm

1
Analyze the requirement for encryption in transit.
The scenario requires securing data in transit between application servers and the database. According to the AWS Shared Responsibility Model, configuring secure connection protocols (SSL/TLS) on the customer's resources is the customer's responsibility.
AWS provides the secure infrastructure, but the customer must configure the network settings, applications, and databases to use secure transport layers.
2
Analyze the requirement for encryption at rest and key policy control.
The customer needs control over key access policies. Using AWS Key Management Service (AWS KMS), the customer must create and configure key policies to determine who can use or manage the keys.
AWS manages the availability and physical security of AWS KMS, but logical control and authorization policies belong to the customer.

Anahtar Kavram

Shared Responsibility Model for Data Protection and Encryption
Bu soruyu puanla