Soru

Zorluk: OrtaShared Responsibility Model

A financial services company is deploying a database workload using Amazon Relational Database Service (Amazon RDS). Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?

  1. A
    Applying security patches and software updates to the database instance's underlying operating system
  2. Configuring database-level user accounts and security group rules to restrict network access to the database instanceCevap
  3. C
    Replacing faulty physical storage drives hosting the database files within the Availability Zone
  4. D
    Performing physical security audits and maintaining facility access controls for the data centers hosting the database

Cevap

Configuring database-level user accounts and security group rules to restrict network access to the database instance
The correct answer is configuring database-level user accounts and security group rules. Under the AWS Shared Responsibility Model for managed services like Amazon RDS, AWS manages the operating system, database engine patching, and the physical infrastructure. The customer remains responsible for securing data access, configuring database-level permissions, and setting up network access control via security groups.

Adım Adım Çözüm

1
Analyze the deployment model of the service mentioned in the scenario.
Amazon RDS is a managed database service (Platform as a Service / PaaS model).
Under the Shared Responsibility Model, AWS manages more of the operational stack for managed services compared to Infrastructure as a Service (IaaS) like Amazon EC2.
2
Determine the boundary of responsibility for Amazon RDS.
AWS is responsible for patching the guest operating system, database engine patching, and managing physical hardware. The customer is responsible for data encryption, database access permissions, and network access configuration (security groups).
AWS manages the platform, but the customer retains ownership and control of their data, access settings, and network rules.
3
Evaluate the given options against this boundary.
Configuring database-level user accounts and security group rules is a customer task, while OS patching, hardware replacement, and data center security are AWS tasks.
This identifies the correct task that falls on the customer's side of the boundary.

Anahtar Kavram

AWS Shared Responsibility Model for Managed Services
Bu soruyu puanla