Soru

Zorluk: OrtaCompliance and Governance

A retail corporation is migrating its point-of-sale systems to AWS and needs to ensure compliance with industry security regulations. Under the AWS Shared Responsibility Model, which of the following compliance-related tasks is the sole responsibility of the customer?

  1. Enforcing password complexity policies and multi-factor authentication for application developersCevap
  2. B
    Verifying the physical access logs of the security personnel at the AWS edge locations
  3. C
    Obtaining custom certifications from AWS auditors for the underlying physical hardware
  4. D
    Using threat detection tools to automatically patch security vulnerabilities in the hypervisor layer

Cevap

Enforcing password complexity policies and multi-factor authentication for application developers
Under the Shared Responsibility Model, the customer is responsible for security and compliance 'in' the cloud. This includes customer-side configurations such as Identity and Access Management (IAM), which encompasses enforcing password complexity policies and enabling multi-factor authentication (MFA) for users.

Adım Adım Çözüm

1
Analyze the scenario to identify the compliance requirement under the AWS Shared Responsibility Model.
The scenario requires identifying a task that falls under customer responsibility ('security in the cloud') rather than AWS responsibility ('security of the cloud').
This establishes the boundary between customer-managed tasks and AWS-managed infrastructure tasks.
2
Evaluate the choices to distinguish between configuration tasks managed by the customer and infrastructure/physical security tasks managed by AWS.
Managing user credentials and IAM access policies (such as password policies and MFA) is a customer responsibility, while physical security, hypervisor patching, and data center compliance are AWS responsibilities.
This identifies the correct task that the customer must perform to satisfy the compliance audit.

Anahtar Kavram

Under the AWS Shared Responsibility Model, compliance is a shared effort. AWS is responsible for the security 'of' the cloud (physical infrastructure, hardware, virtualization layer), while the customer is responsible for security 'in' the cloud (customer data, identity and access management, guest operating systems, and application configurations).
Tahmini Süre:1m 30s
Bu soruyu puanla