Soru

Zorluk: KolayData Protection and Encryption

Under the AWS shared responsibility model, a company wants to ensure that its data is encrypted at rest. Which two tasks are the responsibility of the customer? (Select TWO.)

  1. A
    Upgrading the firmware of physical hardware security modules (HSMs) managed by AWS
  2. Configuring server-side encryption on Amazon S3 bucketsCevap
  3. C
    Replacing failing physical disk drives that contain encrypted data
  4. Managing access policies for AWS Key Management Service (AWS KMS) keysCevap
  5. E
    Managing the physical security of the hardware hosting the key management systems

Cevap

Configuring server-side encryption on Amazon S3 buckets and managing access policies for AWS Key Management Service (AWS KMS) keys.
The tasks of configuring server-side encryption on Amazon S3 buckets and managing access policies for AWS KMS keys are correct because they represent configuration and access control decisions within the customer's AWS account. Under the AWS Shared Responsibility Model, the customer is responsible for configuring security options 'in' the cloud.

Adım Adım Çözüm

1
Determine which aspects of data protection are physical or infrastructure-related.
Physical security, disk replacement, and HSM firmware updates are managed by AWS.
AWS is responsible for security 'of' the cloud, which includes physical data centers, host operating systems, virtualization layers, and physical hardware.
2
Determine which aspects of data protection are configuration or access-related.
Enabling encryption on data storage resources and defining key access permissions are customer responsibilities.
Under the shared responsibility model, the customer is responsible for security 'in' the cloud, which includes data classification, resource configuration, and identity and access management.

Anahtar Kavram

Shared Responsibility Model for Data Protection
Bu soruyu puanla