Soru

Zorluk: KolayData Protection and Encryption

A business analyst is configuring an Amazon Simple Storage Service (Amazon S3) bucket to store financial reports. The company requires that all objects in the bucket be encrypted at rest. Under the AWS shared responsibility model, which of the following tasks is the responsibility of the customer?

  1. Enabling default encryption on the Amazon S3 bucketCevap
  2. B
    Managing the physical security of the storage disks
  3. C
    Provisioning and maintaining dedicated single-tenant cryptographic hardware
  4. D
    Patching the hypervisors running the S3 storage infrastructure

Cevap

Enabling default encryption on the Amazon S3 bucket
Enabling default encryption on the Amazon S3 bucket is correct because the customer is responsible for security 'in' the cloud, which includes configuring data protection features such as encryption settings on S3 buckets. AWS provides the tools, but the customer must enable and configure them.

Adım Adım Çözüm

1
Analyze the requirement under the AWS Shared Responsibility Model for data protection.
Identify that data protection 'in the cloud' (such as configuring encryption settings for S3 buckets) is the customer's responsibility.
AWS protects the infrastructure that runs all of the services offered in the AWS Cloud, while customers are responsible for securing their data within those services.
2
Evaluate the choices to find which action represents a customer configuration task.
The action of enabling default encryption on the S3 bucket is a customer-managed configuration. Other actions like physical security, infrastructure patching, and dedicated hardware maintenance are handled by AWS.
This confirms the correct choice matches customer-side configurations for data protection.

Anahtar Kavram

Under the AWS shared responsibility model, AWS is responsible for security 'of' the cloud (infrastructure, physical security, patching virtualization software), whereas the customer is responsible for security 'in' the cloud (data encryption settings, access controls, configuring resources).
Tahmini Süre:45s
Bu soruyu puanla