A company stores its financial documents in an Amazon Simple Storage Service (Amazon S3) bucket. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
- Enabling server-side encryption on the bucket to protect data at restCevap
- Configuring Amazon S3 bucket policies to restrict access to authorized identitiesCevap
- CReplacing faulty physical storage drives within the AWS data centers
- DUpgrading the underlying operating system of the physical servers hosting Amazon S3
- EContacting the AWS security team directly to request physical data center access audit logs
Cevap
The customer is responsible for enabling server-side encryption on the bucket and configuring S3 bucket policies to restrict access.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. For Amazon S3, this includes managing data encryption configurations (such as enabling server-side encryption) and controlling access to buckets and objects (such as setting up bucket policies and IAM controls).
Adım Adım Çözüm
Anahtar Kavram
Under the AWS Shared Responsibility Model, for managed services like Amazon S3, AWS manages the security 'of' the cloud (physical infrastructure, virtualization layer, operating system), while the customer manages security 'in' the cloud (data encryption, access control policies).
Tahmini Süre:1m 0s