A financial services company uses Amazon S3 Glacier Flexible Retrieval to archive historical transaction records for compliance auditing. Under the AWS Shared Responsibility Model, which of the following security and operational tasks are the sole responsibility of the customer? (Select TWO.)
- Configuring Vault Lock policies to enforce compliance and prevent modification of archivesCevap
- Managing Identity and Access Management (IAM) policies to regulate user access to the vaultCevap
- CDisposing of decommissioned storage media and physical hardware that held the archived data
- DApplying security patches to the host operating system running the storage virtualization layer
- EAccessing AWS compliance certificates and audit reports directly within the Amazon S3 Glacier console
Cevap
The customer is responsible for configuring Vault Lock policies to enforce compliance and managing Identity and Access Management (IAM) policies to regulate user access to the vault.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. For Amazon S3 Glacier, this includes configuring Vault Lock policies to enforce compliance and managing IAM policies to regulate user access. These are control plane configurations managed entirely by the customer.
Adım Adım Çözüm
Anahtar Kavram
Shared Responsibility Model for Managed Services