Soru

Zorluk: ZorShared Responsibility Model

A logistics company is deploying a Redis cluster using Amazon ElastiCache to cache high-frequency tracking data. Under the AWS Shared Responsibility Model, which two of the following operational tasks are the responsibility of the customer?

  1. Configuring Amazon VPC security groups to restrict network access to the cache nodesCevap
  2. Managing database user authentication and access control policies within the Redis applicationCevap
  3. C
    Installing guest operating system updates and security patches on the cache instances
  4. D
    Performing hardware lifecycle replacements for the physical servers hosting the cache nodes
  5. E
    Directly auditing the physical access logs of the AWS data centers where the cache cluster resides

Cevap

Configuring Amazon VPC security groups to restrict network access to the cache nodes, and managing database user authentication and access control policies within the Redis application.
The correct responsibilities of the customer are configuring Amazon VPC security groups to restrict network access to the cache nodes, and managing database user authentication and access control policies within the Redis application. These actions allow the customer to secure access to the service and its data, which falls under security 'in' the cloud.

Adım Adım Çözüm

1
Identify the service deployment model used in the scenario.
Amazon ElastiCache is a managed service (Platform as a Service / PaaS model).
The shared responsibility model boundaries vary depending on whether the service is Infrastructure as a Service (IaaS) like Amazon EC2, or a managed service like Amazon ElastiCache.
2
Determine customer responsibilities for managed caching services.
The customer is responsible for firewall configuration (VPC security groups) and identity and access management within the application (Redis authentication).
In a managed service, AWS manages the operating system, database patching, and physical infrastructure, while the customer retains control over network access rules and application data security.

Anahtar Kavram

In the AWS Shared Responsibility Model, the division of tasks depends on the type of service deployed. For managed services (PaaS) like Amazon ElastiCache, AWS takes on responsibility for the guest operating system, patching, and hardware, while the customer remains responsible for network access controls (security groups) and data access management (user authentication).
Tahmini Süre:2m 0s
Bu soruyu puanla