Soru

Zorluk: OrtaShared Responsibility Model

A financial services company uses Amazon S3 Glacier Flexible Retrieval to archive historical transaction records for compliance auditing. Under the AWS Shared Responsibility Model, which of the following security and operational tasks are the sole responsibility of the customer? (Select TWO.)

  1. Configuring Vault Lock policies to enforce compliance and prevent modification of archivesCevap
  2. Managing Identity and Access Management (IAM) policies to regulate user access to the vaultCevap
  3. C
    Disposing of decommissioned storage media and physical hardware that held the archived data
  4. D
    Applying security patches to the host operating system running the storage virtualization layer
  5. E
    Accessing AWS compliance certificates and audit reports directly within the Amazon S3 Glacier console

Cevap

The customer is responsible for configuring Vault Lock policies to enforce compliance and managing Identity and Access Management (IAM) policies to regulate user access to the vault.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. For Amazon S3 Glacier, this includes configuring Vault Lock policies to enforce compliance and managing IAM policies to regulate user access. These are control plane configurations managed entirely by the customer.

Adım Adım Çözüm

1
Identify the service type and model boundary.
Amazon S3 Glacier is a managed service where AWS handles the underlying infrastructure and virtualization.
Understanding the service type helps distinguish between infrastructure tasks managed by AWS and data/access configurations managed by the customer.
2
Evaluate each operational task against the Shared Responsibility Model.
Vault Lock policies and IAM configurations are data integrity and access control responsibilities (customer's job). Media disposal, host OS patching, and compliance portal access are infrastructure and global compliance responsibilities (AWS's job or AWS Artifact's domain).
This isolates the tasks that fall under customer configuration rather than AWS infrastructure management.

Anahtar Kavram

Shared Responsibility Model for Managed Services
Bu soruyu puanla