Under the AWS shared responsibility model, a company wants to ensure that its data is encrypted at rest. Which two tasks are the responsibility of the customer? (Select TWO.)
- AUpgrading the firmware of physical hardware security modules (HSMs) managed by AWS
- Configuring server-side encryption on Amazon S3 bucketsCevap
- CReplacing failing physical disk drives that contain encrypted data
- Managing access policies for AWS Key Management Service (AWS KMS) keysCevap
- EManaging the physical security of the hardware hosting the key management systems
Cevap
Configuring server-side encryption on Amazon S3 buckets and managing access policies for AWS Key Management Service (AWS KMS) keys.
The tasks of configuring server-side encryption on Amazon S3 buckets and managing access policies for AWS KMS keys are correct because they represent configuration and access control decisions within the customer's AWS account. Under the AWS Shared Responsibility Model, the customer is responsible for configuring security options 'in' the cloud.
Adım Adım Çözüm
Anahtar Kavram
Shared Responsibility Model for Data Protection