Soru

Zorluk: KolayData Protection and Encryption

A retail company is migrating its customer database and product catalogs to Amazon S3. The company's security policy requires that all data stored in the cloud must be encrypted at rest. Under the AWS Shared Responsibility Model, which of the following is a customer responsibility regarding this encryption requirement?

  1. A
    Managing the physical security of the hardware security modules (HSMs) used by AWS Key Management Service (AWS KMS)
  2. B
    Deploying AWS Key Management Service (AWS KMS) when dedicated, single-tenant cryptographic hardware is required for compliance
  3. Configuring server-side encryption on the Amazon S3 buckets using AWS Key Management Service (AWS KMS)Cevap
  4. D
    Patching the underlying operating systems and firmware of the servers hosting the Amazon S3 buckets

Cevap

Configuring server-side encryption on the Amazon S3 buckets using AWS Key Management Service (AWS KMS)
The correct answer is configuring server-side encryption on the Amazon S3 buckets using AWS Key Management Service (AWS KMS). Under the AWS Shared Responsibility Model, the customer is responsible for configuring encryption of data at rest (security 'in' the cloud). This includes selecting and enabling the appropriate encryption settings on their S3 buckets.

Adım Adım Çözüm

1
Determine which security controls are managed by the customer under the Shared Responsibility Model.
The customer is responsible for configuring security options 'in' the cloud, such as enabling server-side encryption on their Amazon S3 buckets.
AWS is responsible for security 'of' the cloud, which includes the physical security of data centers and the underlying infrastructure.
2
Differentiate between customer responsibilities and AWS operational tasks for managed security services.
Tasks like maintaining the physical security of hardware security modules (HSMs) and patching host operating systems of storage servers are handled entirely by AWS.
Managed services like Amazon S3 and AWS KMS offload infrastructure and physical maintenance to AWS.

Anahtar Kavram

Under the AWS Shared Responsibility Model, customers are responsible for data protection and encryption configuration (security 'in' the cloud), while AWS is responsible for physical and infrastructure security (security 'of' the cloud).
Bu soruyu puanla