Soru

Zorluk: OrtaShared Responsibility Model

A media production company has migrated its collaborative design assets from on-premises storage to Amazon FSx for Windows File Server. Under the AWS Shared Responsibility Model, which of the following operational tasks are the sole responsibility of the customer? (Select TWO.)

  1. Configuring security groups to control network traffic to and from the file system.Cevap
  2. Managing file-level and directory-level access control lists (NTFS permissions) for shared folders.Cevap
  3. C
    Applying operating system updates and security patches to the Windows Server instances hosting the file system.
  4. D
    Replacing failed physical storage drives within the underlying storage arrays.
  5. E
    Managing the physical security controls of the data centers hosting the file system.

Cevap

The customer is responsible for configuring security groups to control network traffic to the file system, and managing NTFS permissions for files and folders.
For managed services such as Amazon FSx for Windows File Server, AWS takes responsibility for infrastructure security (security 'of' the cloud), which includes data center physical security, hardware repairs, and operating system updates. The customer remains responsible for security configurations within the service (security 'in' the cloud), such as managing resource-level access permissions (NTFS ACLs) and implementing network access controls through security groups.

Adım Adım Çözüm

1
Identify the AWS service type for Amazon FSx for Windows File Server.
It is a fully managed storage service.
Managed services shift the operational burden of infrastructure, hardware, and OS patching to AWS.
2
Differentiate between customer and AWS responsibilities for this managed service.
AWS handles physical security, hardware replication, and Windows Server OS patching. The customer retains control over network access rules and folder/file permissions.
This classification determines which tasks fall under 'security in the cloud' versus 'security of the cloud'.
3
Select the two options representing customer-managed security tasks.
Configuring security groups and managing NTFS folder permissions are identified as the customer's responsibility.
These are access control configurations executed by the customer within their virtual environment.

Anahtar Kavram

Shared Responsibility Model for Managed Services
Tahmini Süre:1m 30s
Bu soruyu puanla