Soru

Zorluk: Çok zorData Protection and Encryption

A financial technology company must comply with a strict regulatory standard requiring that cryptographic keys used to encrypt transactional data at rest be stored in dedicated, single-tenant hardware security modules (HSMs) where the customer retains exclusive administrative control over the HSM partitions. Which of the following options represents the correct service selection and distribution of responsibility under the AWS Shared Responsibility Model?

  1. A
    AWS Key Management Service (KMS); the customer is responsible for managing the physical security of the multi-tenant HSMs, while AWS manages the creation and rotation of customer-managed keys.
  2. B
    AWS Key Management Service (KMS); AWS provides a dedicated, single-tenant physical HSM for each customer account, while the customer is responsible for upgrading the firmware of the HSM.
  3. AWS CloudHSM; the customer is responsible for managing the HSM users, keys, and cryptographic partitions, while AWS manages the physical hardware maintenance and network availability of the HSM appliance.Cevap
  4. D
    AWS CloudHSM; AWS is responsible for creating HSM database users and generating the cryptographic keys, while the customer manages the network routing and operating system patches of the HSM appliance.

Cevap

AWS CloudHSM is the correct service selection because it provides dedicated, single-tenant HSMs with customer administrative control over the partition. Under this model, the customer is responsible for managing HSM users, keys, and cryptographic configurations, while AWS handles the physical hardware maintenance, network provisioning, and appliance availability.
The correct option correctly identifies AWS CloudHSM as the service that provides dedicated, single-tenant HSM appliances under the customer's exclusive control. It also correctly defines the shared responsibility boundaries where the customer manages the logical aspects (HSM users, keys, partitions) and AWS manages the physical and infrastructure aspects (hardware maintenance and network availability of the appliance).

Adım Adım Çözüm

1
Analyze the compliance requirement for encryption key storage
The requirement specifies dedicated, single-tenant hardware security modules (HSMs) with exclusive customer control over the cryptographic partitions.
To choose between AWS Key Management Service (KMS) and AWS CloudHSM.
2
Evaluate AWS KMS against the requirement
AWS KMS is a managed, multi-tenant service. Even with customer managed keys, the underlying HSMs are shared across multiple tenants. Thus, KMS does not meet the dedicated, single-tenant requirement.
To eliminate KMS-based options.
3
Evaluate AWS CloudHSM against the requirement
AWS CloudHSM provides dedicated, single-tenant HSM instances within the customer's VPC, meeting the compliance requirement.
To confirm AWS CloudHSM as the correct service selection.
4
Determine the distribution of responsibility for AWS CloudHSM
AWS manages physical security, hardware maintenance, network connectivity, and the appliance OS/firmware. The customer manages HSM users, key generation, and partition administration.
To select the correct option that accurately represents the Shared Responsibility Model for AWS CloudHSM.

Anahtar Kavram

AWS CloudHSM vs AWS KMS and the Shared Responsibility Model for cryptographic key storage
Bu soruyu puanla