Soru

Zorluk: OrtaData Protection and Encryption

An online gaming platform is deploying a new database on Amazon EC2 instances to store player profile data. The security team must ensure that all data stored on the EC2 instances' Amazon Elastic Block Store (EBS) volumes is encrypted at rest. According to the AWS Shared Responsibility Model, which of the following is the customer’s responsibility in this scenario?

  1. A
    Managing the physical security of the hardware security modules (HSMs) used to generate keys.
  2. Enabling encryption on the Amazon EBS volumes during creation or at the account level.Cevap
  3. C
    Upgrading the firmware of the physical storage drives hosting the EBS volumes.
  4. D
    Provisioning dedicated single-tenant AWS CloudHSM instances to manage EBS encryption keys by default.

Cevap

Enabling encryption on the Amazon EBS volumes during creation or at the account level.
The correct answer is correct because configuring encryption at rest for storage resources like Amazon EBS volumes falls under security 'in' the cloud, which is the customer's responsibility.

Adım Adım Çözüm

1
Analyze the scenario and identify that the customer is encrypting data at rest on Amazon EBS volumes.
Identify that EBS volume encryption configuration is controlled by the customer.
To determine which part of the task falls under customer control vs. AWS control.
2
Apply the AWS Shared Responsibility Model boundaries to data encryption.
Determine that enabling encryption settings on EBS is security 'in' the cloud (customer responsibility), while maintaining physical infrastructure and hardware security is security 'of' the cloud (AWS responsibility).
To eliminate AWS-managed infrastructure tasks and find the customer action.

Anahtar Kavram

AWS Shared Responsibility Model for Data Encryption at Rest
Bu soruyu puanla