Soru

Zorluk: OrtaData Protection and Encryption

A financial services company is deploying an application on AWS. The application will store credit card transactions in an Amazon S3 bucket and use Amazon RDS for MySQL to manage active customer accounts. The company's compliance policy requires all data to be encrypted at rest and encrypted in transit.

According to the AWS Shared Responsibility Model, which two of the following actions are the responsibility of the customer? (Select TWO.)

  1. Enabling server-side encryption (SSE) on the Amazon S3 bucketCevap
  2. Configuring SSL/TLS connections for data transmitted to the Amazon RDS databaseCevap
  3. C
    Managing the physical security of the hardware security modules (HSMs) that store AWS KMS keys
  4. D
    Replacing failed physical storage drives containing the encrypted RDS database volumes
  5. E
    Provisioning dedicated, single-tenant cryptographic hardware for AWS KMS keys

Cevap

Enabling server-side encryption (SSE) on the Amazon S3 bucket and configuring SSL/TLS connections for data transmitted to the Amazon RDS database are the responsibilities of the customer.
Under the AWS Shared Responsibility Model, the customer is responsible for configuring data protection settings within AWS services. Enabling server-side encryption (SSE) on the Amazon S3 bucket protects data at rest, while configuring SSL/TLS connections for the Amazon RDS database protects data in transit. Both are customer-controlled configurations.

Adım Adım Çözüm

1
Identify the service data protection requirements in the scenario.
The scenario requires encryption at rest for Amazon S3 and Amazon RDS, and encryption in transit for database traffic.
To classify responsibilities, we must first identify what security features are being configured.
2
Apply the AWS Shared Responsibility Model to the identified tasks.
Configuring encryption settings (such as enabling SSE on S3 and setting up SSL/TLS for database connections) is 'security in the cloud' and thus a customer responsibility. Managing hardware security, replacing disk drives, and provisioning KMS multi-tenant infrastructure is 'security of the cloud' and thus AWS's responsibility.
Distinguishing between customer responsibilities (logical configuration and data protection) and AWS responsibilities (physical infrastructure and service management) determines the correct options.

Anahtar Kavram

Under the AWS Shared Responsibility Model, AWS manages security *of* the cloud (physical infrastructure, virtualization layer, and global infrastructure). The customer is responsible for security *in* the cloud, which includes data protection (encryption at rest and in transit) and access management.

AreaCustomer Responsibility (Security IN the Cloud)AWS Responsibility (Security OF the Cloud)
Data at RestEnabling server-side encryption (SSE), managing customer master keys (CMKs)Physical security of HSMs, media disposal, physical storage maintenance
Data in TransitConfiguring SSL/TLS, managing network traffic encryptionMaintaining the physical network and AWS global infrastructure
Tahmini Süre:1m 30s
Bu soruyu puanla