A financial institution is deploying a payment gateway on AWS. The institution's compliance policy dictates that all customer transactions must be encrypted at rest using single-tenant cryptographic hardware under the institution's exclusive control. Additionally, all transactional data must be encrypted in transit across all application tiers.
Under the AWS Shared Responsibility Model, which of the following are responsibilities of the customer to meet these security requirements? (Select TWO.)
- Generating and managing the cryptographic keys and user accounts within an AWS CloudHSM instanceCevap
- BSecuring the physical infrastructure and power supply of the host data centers housing the cryptographic hardware
- CConfiguring AWS Key Management Service (AWS KMS) to provide dedicated, single-tenant hardware security modules (HSMs)
- Configuring SSL/TLS parameters to secure data in transit between application layersCevap
- EManaging the physical lifecycle and firmware updates of the hardware security modules (HSMs)
Cevap
Generating and managing the cryptographic keys and user accounts within an AWS CloudHSM instance, and configuring SSL/TLS parameters to secure data in transit between application layers.
Generating and managing keys inside AWS CloudHSM is a customer responsibility because CloudHSM provides dedicated cryptographic hardware where the customer has sole control over keys and users. Configuring SSL/TLS parameters for data in transit is also a customer responsibility because it is configured at the application and operating system level, which falls under customer control in the AWS Shared Responsibility Model.
Adım Adım Çözüm
Anahtar Kavram
Under the AWS Shared Responsibility Model, the customer is responsible for configuring encryption in transit (SSL/TLS) and managing their cryptographic keys and user accounts within single-tenant hardware like AWS CloudHSM, while AWS handles physical infrastructure and hardware maintenance.
Tahmini Süre:2m 0s