Soru

Zorluk: KolayShared Responsibility Model

A technology startup runs its backend API on AWS Lambda. Under the AWS Shared Responsibility Model, which of the following security tasks is the responsibility of the startup?

  1. A
    Patching the underlying operating system and runtime environments
  2. B
    Maintaining the physical security of the servers hosting the Lambda service
  3. C
    Upgrading the virtualization hypervisor software on the physical hosts
  4. Configuring Identity and Access Management (IAM) execution roles for the Lambda functionsCevap

Cevap

Configuring Identity and Access Management (IAM) execution roles for the Lambda functions
Configuring IAM execution roles for Lambda functions is the customer's responsibility. Under the AWS Shared Responsibility Model, identity and access management (IAM) remains a customer responsibility across all service types, ensuring that only authorized users or processes can access the resource.

Adım Adım Çözüm

1
Identify the service model of AWS Lambda.
AWS Lambda is a serverless, abstracted service.
The level of customer responsibility depends on whether the service is categorized as infrastructure (IaaS), container/platform (PaaS), or abstract/serverless.
2
Evaluate the customer's responsibility boundary for a serverless service.
AWS manages the infrastructure layer (hardware, virtualization, operating system, and runtime). The customer retains responsibility for configuring access controls, writing code, and protecting their data.
Under the Shared Responsibility Model, even when infrastructure management is offloaded to AWS, IAM configuration remains the customer's responsibility.

Anahtar Kavram

AWS Shared Responsibility Model for serverless/abstracted services
Bu soruyu puanla