A telecommunications company is migrating its customer billing system to AWS. The security policy mandates that all database backups stored in Amazon S3 must be encrypted at rest using encryption keys managed within dedicated, single-tenant hardware security modules (HSMs) to comply with local regulations. Additionally, the company wants to ensure this encryption strategy complies with the AWS Shared Responsibility Model.
Which of the following options correctly identify a service or responsibility required for this architecture? (Select TWO.)
- AWS CloudHSM to manage the encryption keys on dedicated, single-tenant hardware security modules.Cevap
- The customer's responsibility to configure the server-side encryption settings on the Amazon S3 buckets.Cevap
- CAWS Key Management Service (AWS KMS) with AWS-managed keys to provide dedicated, single-tenant cryptographic storage.
- DAWS's responsibility to automatically configure and enable encryption on all customer-created Amazon S3 buckets.
- EAWS Certificate Manager (ACM) to generate and rotate symmetric encryption keys for data at rest.
Cevap
AWS CloudHSM to manage the encryption keys on dedicated, single-tenant hardware security modules, and the customer's responsibility to configure the server-side encryption settings on the Amazon S3 buckets.
AWS CloudHSM provides dedicated, single-tenant hardware security modules (HSMs) directly under the customer's control, which satisfies the compliance requirement. Additionally, under the Shared Responsibility Model, configuring data protection settings like server-side encryption on Amazon S3 buckets falls under the customer's responsibility (security in the cloud).
Adım Adım Çözüm
Anahtar Kavram
AWS CloudHSM vs AWS KMS single-tenant requirements and the customer's role in data encryption under the AWS Shared Responsibility Model
Tahmini Süre:1m 30s