Soru

Zorluk: OrtaShared Responsibility Model

A small retail business is deploying a new online storefront using Amazon Lightsail virtual private servers. Under the AWS Shared Responsibility Model, which two security-related tasks are the responsibility of the customer? (Select TWO)

  1. Upgrading and patching the guest operating system installed on the instancesCevap
  2. Configuring the instance-level firewall rules to control inbound and outbound network trafficCevap
  3. C
    Updating the virtualization hypervisor software that manages the host physical servers
  4. D
    Replacing failed physical hard drives and storage arrays in the AWS data center
  5. E
    Conducting physical audits of AWS facilities to certify compliance with ISO and PCI DSS standards

Cevap

The customer is responsible for upgrading and patching the guest operating system installed on the instances, as well as configuring the instance-level firewall rules to control inbound and outbound network traffic.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. For virtual private servers like Amazon Lightsail, the customer has control over the guest operating system and the local network configurations. Therefore, patching the guest operating system and configuring the firewall rules to control traffic are both customer responsibilities.

Adım Adım Çözüm

1
Identify the AWS service type in the scenario
Amazon Lightsail is an Infrastructure as a Service (IaaS) resource.
Different service types (IaaS vs. PaaS vs. SaaS/Managed) shift the shared responsibility boundary between AWS and the customer.
2
Determine the customer's responsibility boundary for IaaS resources
For IaaS resources, the customer is responsible for the guest operating system, application software, data configuration, and local network settings (firewalls).
Since the customer maintains administrative access to the OS and network settings, security 'in' the cloud at these layers is their responsibility.
3
Determine the AWS responsibility boundary
AWS is responsible for physical hardware, data centers, virtualization software (hypervisor), and core infrastructure services.
AWS manages the global infrastructure and physical assets that host customer services (security 'of' the cloud).

Anahtar Kavram

The division of security duties between AWS (security of the cloud) and the customer (security in the cloud) under the AWS Shared Responsibility Model, specifically for IaaS/VPS platforms.
Bu soruyu puanla