A government contractor is deploying an application on AWS that handles classified public safety records. Compliance regulations mandate that all data at rest must be encrypted using cryptographic keys stored inside dedicated, single-tenant hardware security modules (HSMs) that are physically and logically isolated. Which option correctly identifies the AWS service that meets this requirement and the customer's responsibility for that service under the AWS Shared Responsibility Model?
- AWS CloudHSM; the customer is responsible for managing users, keys, and cryptographic partitions on the dedicated HSM instance.Cevap
- BAWS Key Management Service (AWS KMS); the customer is responsible for managing the physical security and climate control of the hardware security modules.
- CAWS CloudHSM; the customer is responsible for performing firmware updates, physical hardware maintenance, and patching the appliance operating system.
- DAWS Key Management Service (AWS KMS); the customer is responsible for configuring logical partitions and key policies directly on the physical hardware security modules.
Cevap
AWS CloudHSM; the customer is responsible for managing users, keys, and cryptographic partitions on the dedicated HSM instance.
AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud. It provides dedicated, single-tenant HSM instances under the customer's direct control. Under the AWS Shared Responsibility Model, AWS manages physical security, hardware provisioning, and network connectivity, while the customer maintains sole control over the cryptographic keys, partitions, and user management.
Adım Adım Çözüm
Anahtar Kavram
AWS CloudHSM vs AWS KMS and the Shared Responsibility Model for dedicated cryptography.
Tahmini Süre:1m 0s