Soru

Zorluk: ZorShared Responsibility Model

A pharmaceutical company deploys an AWS Outpost in its on-premises data center to comply with local data residency regulations. The IT team is establishing the operational security procedures for this hybrid deployment. Under the AWS Shared Responsibility Model, which two duties remain the responsibility of the customer? (Select TWO.)

  1. Providing physical security, power, and cooling for the Outpost hardware rackCevap
  2. Configuring security groups and network access control lists (NACLs) to regulate traffic within the virtual private cloud (VPC) on the OutpostCevap
  3. C
    Replacing failed physical components, such as power supply units or disk drives, in the Outpost rack
  4. D
    Patching and maintaining the virtualization hypervisor software installed on the Outpost
  5. E
    Requesting on-site physical security audits from AWS to certify the data center facility hosting the Outpost

Cevap

The customer is responsible for providing physical security, power, and cooling for the Outpost hardware rack, as well as configuring security groups and network access control lists (NACLs) to regulate traffic within the virtual private cloud (VPC) on the Outpost.
For AWS Outposts, because the physical rack is situated inside the customer's premises, the customer is responsible for physical security, power, and cooling. Additionally, the customer retains control over logical security controls in the cloud, such as security groups and network access control lists (NACLs) for virtual network resources.

Adım Adım Çözüm

1
Analyze the service deployment model for AWS Outposts.
AWS Outposts is a hybrid service where AWS-managed hardware is installed in a customer-owned physical facility.
Understanding the hybrid nature of AWS Outposts is necessary to identify how the boundary of physical responsibility shifts compared to standard AWS region deployments.
2
Differentiate the physical security responsibilities.
Since the hardware resides in the customer's facility, the customer must manage physical security, power, and cooling, while AWS remains responsible for hardware replacement and maintenance.
This establishes the physical security boundary under the Shared Responsibility Model for AWS Outposts.
3
Differentiate the logical network and infrastructure responsibilities.
AWS manages the hypervisor and Outpost firmware, while the customer manages virtual private cloud (VPC) configurations, including security groups and network ACLs.
This determines which network configurations are handled by the customer.

Anahtar Kavram

Shared Responsibility Model for Hybrid Cloud (AWS Outposts)
Bu soruyu puanla