A financial technology company must comply with a strict regulatory standard requiring that cryptographic keys used to encrypt transactional data at rest be stored in dedicated, single-tenant hardware security modules (HSMs) where the customer retains exclusive administrative control over the HSM partitions. Which of the following options represents the correct service selection and distribution of responsibility under the AWS Shared Responsibility Model?
- AAWS Key Management Service (KMS); the customer is responsible for managing the physical security of the multi-tenant HSMs, while AWS manages the creation and rotation of customer-managed keys.
- BAWS Key Management Service (KMS); AWS provides a dedicated, single-tenant physical HSM for each customer account, while the customer is responsible for upgrading the firmware of the HSM.
- AWS CloudHSM; the customer is responsible for managing the HSM users, keys, and cryptographic partitions, while AWS manages the physical hardware maintenance and network availability of the HSM appliance.Cevap
- DAWS CloudHSM; AWS is responsible for creating HSM database users and generating the cryptographic keys, while the customer manages the network routing and operating system patches of the HSM appliance.
Cevap
AWS CloudHSM is the correct service selection because it provides dedicated, single-tenant HSMs with customer administrative control over the partition. Under this model, the customer is responsible for managing HSM users, keys, and cryptographic configurations, while AWS handles the physical hardware maintenance, network provisioning, and appliance availability.
The correct option correctly identifies AWS CloudHSM as the service that provides dedicated, single-tenant HSM appliances under the customer's exclusive control. It also correctly defines the shared responsibility boundaries where the customer manages the logical aspects (HSM users, keys, partitions) and AWS manages the physical and infrastructure aspects (hardware maintenance and network availability of the appliance).
Adım Adım Çözüm
Anahtar Kavram
AWS CloudHSM vs AWS KMS and the Shared Responsibility Model for cryptographic key storage