Soru

Zorluk: OrtaShared Responsibility Model

A logistics company is using Amazon Simple Queue Service (SQS) to decouple its order processing systems. Under the AWS Shared Responsibility Model, which TWO of the following tasks are the responsibility of the customer? (Select TWO.)

  1. Configuring IAM policies to authorize specific applications and microservices to send and receive messages from the queuesCevap
  2. Configuring server-side encryption (SSE) for the queues and managing the access permissions of the associated KMS keysCevap
  3. C
    Patching and upgrading the operating system of the virtual instances running the message queue software
  4. D
    Replicating message queue data across multiple Availability Zones to ensure high availability and durability
  5. E
    Retrieving the SOC 2 compliance reports for the SQS infrastructure by creating a custom query in Amazon CloudWatch Logs

Cevap

Configuring IAM policies to authorize specific applications and microservices, and configuring server-side encryption (SSE) for the queues.
Under the AWS Shared Responsibility Model, customers are responsible for securing their data and access to resources (security 'in' the cloud). For a managed service like Amazon SQS, this includes defining IAM policies to regulate queue access and configuring server-side encryption (SSE) along with permissions for AWS KMS keys. AWS maintains the security 'of' the cloud, managing SQS server OS patches, infrastructure scaling, and message replication.

Adım Adım Çözüm

1
Differentiate between customer-managed tasks and AWS-managed tasks for fully managed services under the Shared Responsibility Model.
Identify that AWS manages host OS patching and queue replication across Availability Zones.
This rules out tasks related to physical infrastructure and service maintenance.
2
Determine tasks that fall under customer-controlled data protection and access management configurations.
Identify that configuring IAM policies and enabling KMS encryption keys are customer responsibilities.
This establishes the correct actions for securing queue access and data.
3
Analyze how AWS compliance reports are retrieved and audited.
Determine that reports are obtained via AWS Artifact rather than querying CloudWatch Logs.
This eliminates the incorrect auditing method option.

Anahtar Kavram

Shared Responsibility Model for Managed Services
Bu soruyu puanla