Soru

Zorluk: OrtaData Protection and Encryption

A digital publishing company is storing sensitive author manuscripts in an Amazon S3 bucket. The company mandates the use of server-side encryption with AWS Key Management Service (SSE-KMS) to protect the data at rest. Under the AWS Shared Responsibility Model, which of the following security-related tasks is the responsibility of the customer?

  1. Defining and managing the key policies that control access to the encryption keysCevap
  2. B
    Managing the physical security of the hardware security modules (HSMs) hosting the KMS service
  3. C
    Patching and maintaining the underlying operating systems of the KMS infrastructure
  4. D
    Provisioning a dedicated AWS CloudHSM instance to store the customer managed keys

Cevap

Defining and managing the key policies that control access to the encryption keys
The correct answer is correct because configuring key policies determines who can access the keys, which is a customer-side configuration control under the Shared Responsibility Model.

Adım Adım Çözüm

1
Analyze the encryption requirement in the scenario.
The scenario requires using server-side encryption with AWS KMS (SSE-KMS) on Amazon S3.
This establishes that the service in use is AWS Key Management Service (KMS), which is an AWS-managed service.
2
Apply the Shared Responsibility Model boundaries to the KMS service.
AWS is responsible for physical security, hardware maintenance, and patching the host OS. The customer is responsible for configuring access policies, key rotation, and usage permissions.
This helps isolate customer duties from AWS duties.
3
Evaluate the choices to identify the task managed by the customer.
Defining key policies is a customer configuration task, whereas physical security, OS patching, and dedicated HSM provisioning do not apply to the customer's KMS configuration.
This yields the correct answer and identifies why other choices represent AWS responsibilities or incorrect service mappings.

Anahtar Kavram

The AWS Shared Responsibility Model specifies that for managed services like AWS KMS, AWS manages the underlying infrastructure and physical security, while the customer manages access policies and key configurations.
Tahmini Süre:1m 15s
Bu soruyu puanla