Soru

Zorluk: OrtaAWS Compute Services

A company is planning to deploy a containerized application on AWS. Due to regulatory compliance, the company's security policy requires them to install custom host-based security monitoring agents directly on the host operating system running the container workloads. Which AWS compute solution should the company select to manage the containers while satisfying this requirement?

  1. Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch typeCevap
  2. B
    Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type
  3. C
    AWS Lambda
  4. D
    Amazon Lightsail container services

Cevap

Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type
The correct answer is Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type. In this model, the customer is responsible for managing the EC2 instances that register into the ECS cluster. Because the customer owns these instances, they have full administrative (root) access to the host operating system, making it possible to install custom security monitoring agents. Amazon ECS handles the orchestration of the containers on top of these instances.

Adım Adım Çözüm

1
Analyze the workload packaging and administrative requirements.
The application is containerized, and the customer requires host-level operating system access to install custom security agents.
Identifying these requirements helps filter out serverless or fully managed solutions where AWS manages and restricts access to the underlying host OS.
2
Evaluate the launch types and services against the customer's shared responsibility model boundaries.
Amazon ECS with the Amazon EC2 launch type allows the customer to provision and manage the EC2 instances, giving them complete administrative control over the OS. AWS Fargate, AWS Lambda, and Amazon Lightsail container services abstract the host OS completely, preventing any custom host-level software installations.
Matching the administrative requirements to the corresponding AWS compute model ensures compliance with the custom security agent policy.

Anahtar Kavram

AWS Compute Services - Shared Responsibility and OS Access in Containers
Tahmini Süre:1m 30s
Bu soruyu puanla