Soru

Zorluk: Çok zorShared Responsibility Model

A financial services institution deploys an AWS Outposts rack in its on-premises data center to run latency-sensitive algorithmic trading applications. Under the AWS Shared Responsibility Model, which TWO tasks are the responsibility of the customer?

  1. Providing physical access security, electrical power, and cooling (HVAC) for the Outposts hardware within the local facilityCevap
  2. Configuring security groups and network access control lists (NACLs) to regulate traffic to and from the instances deployed on the OutpostCevap
  3. C
    Replacing failed physical components, such as memory modules or power supplies, in the Outpost rack
  4. D
    Patching and upgrading the virtualization hypervisor software running on the Outpost hosts
  5. E
    Retrieving official AWS compliance reports directly from the Outposts physical management interface

Cevap

The customer is responsible for providing physical access security, electrical power, and cooling (HVAC) for the Outposts hardware within the local facility, as well as configuring security groups and network access control lists (NACLs) to regulate traffic to and from the instances deployed on the Outpost.
Under the Shared Responsibility Model for AWS Outposts, the customer is responsible for securing the physical location, power, and cooling of the Outposts rack at their site. In addition, the customer is responsible for configuring security groups and network access control lists to regulate traffic flow to and from the instances. AWS maintains responsibility for the infrastructure software, including the virtualization hypervisor, and performs physical hardware replacements.

Adım Adım Çözüm

1
Analyze the deployment architecture and physical location of the resources.
AWS Outposts is a hybrid service where physical hardware owned by AWS is placed within the customer's local on-premises facility.
Shared responsibility boundaries shift when physical infrastructure is housed outside of AWS data centers.
2
Differentiate physical responsibilities between standard AWS regions and AWS Outposts.
Unlike standard services where AWS manages physical data center security, utility power, and HVAC, for Outposts, these site environmental and physical security responsibilities belong to the customer.
AWS has no physical access or control over the customer's on-premises building.
3
Identify logical and virtual resources control responsibilities.
The customer is responsible for configuring security groups and network access control lists (NACLs) to secure logical network traffic.
AWS provides the software-defined networking capability, but the configuration of access rules remains under customer control.
4
Differentiate physical hardware maintenance responsibilities.
AWS is responsible for physical component replacement and hypervisor patching.
AWS manages the infrastructure lifecycle and updates of the Outposts service as a fully managed offering.

Anahtar Kavram

AWS Shared Responsibility Model for AWS Outposts
Bu soruyu puanla