A company is implementing a data protection policy for its applications running on AWS. The security team needs to understand the division of responsibility for data protection under the AWS Shared Responsibility Model.
Which of the following are responsibilities of the customer? (Select TWO.)
- Encrypting customer data at rest within AWS storage servicesCevap
- BManaging the physical security of the host virtualization layer
- Configuring SSL/TLS for encrypting data in transitCevap
- DDisposing of decommissioned physical hard drives
- EMaintaining the physical facilities and data center security
Cevap
Under the AWS Shared Responsibility Model, the customer is responsible for encrypting customer data at rest within AWS storage services and configuring SSL/TLS for encrypting data in transit.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. This includes protecting their own data, which requires them to configure encryption at rest within AWS storage services and establish SSL/TLS encryption for data in transit.
Adım Adım Çözüm
Anahtar Kavram
Under the AWS Shared Responsibility Model, AWS is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud. The customer is responsible for managing their data (including encryption options), classified as security 'in' the cloud.