Soru

Zorluk: ZorShared Responsibility Model

A financial services organization is deploying AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to enable single sign-on (SSO) for its cloud-based workloads. According to the AWS Shared Responsibility Model, which of the following tasks are the responsibility of the customer? (Select TWO.)

  1. Configuring trust relationships between the AWS Managed Microsoft AD domain and the organization's on-premises Active Directory domains.Cevap
  2. Creating and managing Active Directory users, groups, and Group Policy Objects (GPOs) within the directory.Cevap
  3. C
    Applying monthly security patches and operating system updates to the domain controller instances.
  4. D
    Configuring stateless Network Access Control Lists (NACLs) to manage traffic at the instance level for individual domain controllers.
  5. E
    Generating physical security compliance documentation for the AWS data centers where the directory servers reside.

Cevap

The customer is responsible for configuring trust relationships between the AWS Managed AD domain and on-premises domains, and creating and managing Active Directory users, groups, and Group Policy Objects (GPOs) within the directory.
For AWS Managed Microsoft AD, the customer is responsible for defining directory configurations, which includes establishing trust relationships with on-premises directories and managing organizational units, users, groups, and Group Policy Objects (GPOs) inside the directory.

Adım Adım Çözüm

1
Identify the service classification under the AWS Shared Responsibility Model.
AWS Managed Microsoft AD is a managed service. Under this model, AWS manages the physical security, infrastructure, and operating system of the domain controllers, while the customer manages directory content and access configuration.
Managed services shift infrastructure management tasks, such as OS patching, from the customer to AWS.
2
Determine which options represent customer configuration rather than infrastructure maintenance.
Configuring domain trusts and managing AD objects (users, groups, GPOs) are configuration tasks. Patching domain controller operating systems, configuring subnet-level network rules at the instance level, and compiling data center physical compliance documentation are handled by AWS.
This isolates the administrative directory management duties that remain the customer's responsibility.

Anahtar Kavram

Shared Responsibility Model for Managed Services
Tahmini Süre:2m 0s
Bu soruyu puanla