Soru

Zorluk: OrtaData Protection and Encryption

A government contractor is deploying an application on AWS that handles classified public safety records. Compliance regulations mandate that all data at rest must be encrypted using cryptographic keys stored inside dedicated, single-tenant hardware security modules (HSMs) that are physically and logically isolated. Which option correctly identifies the AWS service that meets this requirement and the customer's responsibility for that service under the AWS Shared Responsibility Model?

  1. AWS CloudHSM; the customer is responsible for managing users, keys, and cryptographic partitions on the dedicated HSM instance.Cevap
  2. B
    AWS Key Management Service (AWS KMS); the customer is responsible for managing the physical security and climate control of the hardware security modules.
  3. C
    AWS CloudHSM; the customer is responsible for performing firmware updates, physical hardware maintenance, and patching the appliance operating system.
  4. D
    AWS Key Management Service (AWS KMS); the customer is responsible for configuring logical partitions and key policies directly on the physical hardware security modules.

Cevap

AWS CloudHSM; the customer is responsible for managing users, keys, and cryptographic partitions on the dedicated HSM instance.
AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud. It provides dedicated, single-tenant HSM instances under the customer's direct control. Under the AWS Shared Responsibility Model, AWS manages physical security, hardware provisioning, and network connectivity, while the customer maintains sole control over the cryptographic keys, partitions, and user management.

Adım Adım Çözüm

1
Identify the key residency and tenancy requirement.
The requirements mandate dedicated, single-tenant hardware security modules (HSMs), which points to AWS CloudHSM instead of AWS Key Management Service (AWS KMS) which uses shared, multi-tenant HSMs.
AWS CloudHSM provides dedicated HSM instances, whereas AWS KMS is a multi-tenant service.
2
Determine the shared responsibility model boundary for the chosen service.
For AWS CloudHSM, AWS manages hardware provisioning, physical security, and high availability, while the customer manages HSM partitions, cryptographic users, and key generation.
To satisfy the compliance requirements, the customer must maintain exclusive administrative control over the keys and users on the single-tenant HSM.

Anahtar Kavram

AWS CloudHSM vs AWS KMS and the Shared Responsibility Model for dedicated cryptography.
Tahmini Süre:1m 0s
Bu soruyu puanla