Soru

Zorluk: KolayData Protection and Encryption

A gaming company is migrating its leaderboard database to AWS. The company needs to encrypt the database backups stored in Amazon S3 at rest and ensure that all data sent to the database is encrypted in transit. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer?

  1. Enabling server-side encryption on the Amazon S3 buckets.Cevap
  2. B
    Managing the physical security of AWS data centers that house encryption keys.
  3. Configuring SSL/TLS on client applications to encrypt data in transit.Cevap
  4. D
    Provisioning a dedicated AWS CloudHSM cluster to handle default S3-managed encryption keys.
  5. E
    Replacing failed storage media containing the encrypted database backups.

Cevap

Enabling server-side encryption on the Amazon S3 buckets and configuring SSL/TLS on client applications to encrypt data in transit.
Under the AWS Shared Responsibility Model, the customer is responsible for 'security in the cloud'. This includes configuring data protection settings such as enabling server-side encryption on Amazon S3 buckets to protect data at rest, and implementing SSL/TLS on client applications to protect data in transit. AWS is responsible for 'security of the cloud', which includes physical security of the infrastructure.

Adım Adım Çözüm

1
Determine which tasks relate to customer-managed configurations in the cloud versus the underlying infrastructure managed by AWS.
Configuring S3 encryption settings and application network protocols are customer tasks, while physical data center security and hardware replacement are managed by AWS.
The AWS Shared Responsibility Model divides tasks into security 'in' the cloud (customer responsibility) and security 'of' the cloud (AWS responsibility).
2
Analyze key management options to identify the correct usage of encryption services.
Standard S3-managed encryption (SSE-S3) does not require provisioning a dedicated single-tenant hardware security module (AWS CloudHSM).
AWS CloudHSM is a dedicated hardware module, whereas default S3 encryption is managed automatically by AWS without infrastructure provisioning.

Anahtar Kavram

Under the AWS Shared Responsibility Model, customers are responsible for encrypting their data in transit (using protocols like SSL/TLS) and configuring encryption at rest (such as enabling server-side encryption on S3 buckets).
Bu soruyu puanla