Soru

Zorluk: KolayData Protection and Encryption

A logistics company is building a package tracking system on AWS. The company's security policy requires that all package destination logs must be encrypted at rest. Which of the following are customer responsibilities for protecting this data? (Select TWO.)

  1. Enabling encryption on the AWS storage services where the logs are storedCevap
  2. Managing access permissions for the keys used to encrypt the logsCevap
  3. C
    Securing the physical data centers where the storage drives are housed
  4. D
    Replacing failed physical storage hardware that contains encrypted data
  5. E
    Provisioning AWS CloudHSM to automatically manage key rotation and access policies for all AWS services

Cevap

Under the AWS Shared Responsibility Model, the customer is responsible for enabling encryption on the storage services where their logs reside, and managing the access permissions for the keys used to encrypt those logs.
Under the AWS Shared Responsibility Model, customers are responsible for data protection settings within the services they use ('security in the cloud'). This includes configuring encryption at rest for storage resources (such as Amazon S3 buckets or Amazon EBS volumes) and managing access permissions for the cryptographic keys used to encrypt that data. AWS, on the other hand, is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud ('security of the cloud').

Adım Adım Çözüm

1
Identify the boundary between customer responsibility and AWS responsibility regarding data protection.
Recognize that 'security in the cloud' (such as configuring encryption on storage services and managing key access) is the customer's responsibility, while 'security of the cloud' (physical security and hardware maintenance) is AWS's responsibility.
This helps eliminate options that involve physical data center security or hardware replacements.
2
Evaluate the remaining options to identify correct key management and encryption practices.
Confirm that configuring encryption on storage services and managing key permissions are correct customer duties, whereas AWS CloudHSM is a dedicated service requiring manual key administration rather than automatic global service integration.
This isolates the two correct actions.

Anahtar Kavram

AWS Shared Responsibility Model for Data Encryption
Tahmini Süre:45s
Bu soruyu puanla