Soru

Zorluk: OrtaShared Responsibility Model

A retail enterprise connects its on-premises data center to an AWS Virtual Private Cloud (VPC) using an AWS Site-to-Site VPN. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?

  1. Configuring and maintaining the physical customer gateway device at the on-premises data centerCevap
  2. B
    Patching the underlying host operating system of the virtual private gateway endpoints within the AWS infrastructure
  3. C
    Associating stateful security groups directly to the Virtual Private Gateway to control incoming traffic from the VPN
  4. D
    Requesting AWS to perform a physical security audit of the data centers housing the VPN hardware

Cevap

Configuring and maintaining the physical customer gateway device at the on-premises data center
The customer gateway is a physical device or software application on the customer's side of the connection (on-premises). Under the Shared Responsibility Model, the customer maintains full ownership and operational responsibility for their physical assets, configuration, and security outside of the AWS global infrastructure.

Adım Adım Çözüm

1
Analyze the components of the AWS Site-to-Site VPN connection.
The connection consists of a customer-side component (customer gateway) and an AWS-side component (virtual private gateway).
Identifying the boundary between on-premises infrastructure and AWS resources is key to determining responsibility.
2
Apply the Shared Responsibility Model guidelines to the components.
The customer is responsible for the security and configuration of resources they own and control (on-premises gateway), while AWS is responsible for the security 'of' the cloud (virtual private gateway hosting, physical security of AWS data centers).
This determines that the physical customer gateway management is the customer's task.

Anahtar Kavram

Shared Responsibility Model boundary for hybrid networking components
Bu soruyu puanla