Soru

Zorluk: OrtaData Protection and Encryption

A smart home IoT startup is deploying an application on AWS to collect and store telemetry data. The startup's security policy requires encrypting all data at rest using AWS Key Management Service (AWS KMS). Under the AWS Shared Responsibility Model, which of the following represent the responsibilities of the customer and AWS regarding encryption and key management? (Select TWO)

  1. Defining the key policies that control access to AWS Key Management Service (AWS KMS) customer managed keysCevap
  2. Maintaining the physical security and infrastructure of the hardware security modules (HSMs) that back AWS Key Management Service (AWS KMS)Cevap
  3. C
    Performing hardware maintenance and firmware updates on the physical HSMs hosting AWS Key Management Service (AWS KMS)
  4. D
    Configuring AWS Key Management Service (AWS KMS) to provide dedicated, single-tenant hardware security modules with operating system-level control
  5. E
    Automatically rotating and managing custom cryptographic key material imported by the customer into AWS Key Management Service (AWS KMS)

Cevap

The customer is responsible for defining the key policies that control access to customer managed keys, and AWS is responsible for maintaining the physical security and infrastructure of the hardware security modules (HSMs) backing AWS Key Management Service (AWS KMS).
Defining key policies is a customer responsibility under the Shared Responsibility Model to secure access to customer managed keys. AWS is responsible for the physical security and operations of the underlying HSM infrastructure that supports AWS KMS.

Adım Adım Çözüm

1
Identify the shared responsibility boundary for AWS Key Management Service (AWS KMS).
AWS manages the physical security, hardware, and operational lifecycle of the HSMs, while the customer manages key configuration, access control, and usage.
AWS KMS is a managed service, meaning AWS handles infrastructure management while the customer manages data and configuration.
2
Compare customer managed keys access control.
Customers must define policies (key policies, IAM policies) to specify who can use or administer the keys.
AWS does not automatically configure user access permissions for customer managed keys.
3
Analyze physical hardware and service differences.
AWS CloudHSM, not AWS KMS, provides dedicated, single-tenant HSMs with OS-level control. Also, imported key material is managed and rotated by the customer, not AWS.
Distinguishing KMS from CloudHSM and understanding key rotation limitations ensures correct mapping of responsibilities.

Anahtar Kavram

Shared responsibility and operational characteristics of AWS Key Management Service (AWS KMS) versus AWS CloudHSM.
Tahmini Süre:1m 30s
Bu soruyu puanla