Soru

Zorluk: OrtaData Protection and Encryption

A ride-sharing company is deploying an application on AWS that processes passenger location coordinates. To ensure data privacy, the developer wants to encrypt this coordinate data while it is transmitted from the passenger's mobile app to the application backend on AWS. Under the AWS Shared Responsibility Model, which of the following is the customer's responsibility in this scenario?

  1. A
    Encrypting the physical fiber-optic cables that connect AWS edge locations
  2. B
    Managing the physical security of the network switches inside AWS data centers
  3. Configuring SSL/TLS certificates and protocols on the application endpointsCevap
  4. D
    Deploying dedicated AWS CloudHSM instances to automatically manage all mobile network encryption

Cevap

Configuring SSL/TLS certificates and protocols on the application endpoints
Under the AWS Shared Responsibility Model, the customer is responsible for protecting data in transit ('Security in the Cloud'). This includes configuring SSL/TLS certificates and secure protocols (like HTTPS) on their application endpoints, such as load balancers, API gateways, or EC2 instances.

Adım Adım Çözüm

1
Analyze the security requirement: the company needs to encrypt coordinate data in transit between mobile apps and the AWS backend.
Identified encryption in transit as the primary security goal.
Understanding the context helps determine which security controls are applicable.
2
Apply the AWS Shared Responsibility Model to data in transit.
Determine that while AWS secures the underlying physical network infrastructure, the customer is responsible for configuring encryption protocols on their logical endpoints.
This isolates the boundary between AWS infrastructure security and customer data/application configuration.
3
Identify the correct option that reflects this customer-side configuration.
Configuring SSL/TLS certificates on endpoints like Application Load Balancers or API Gateways matches the customer's responsibility.
This implements the required encryption in transit at the application layer.

Anahtar Kavram

Shared Responsibility Model for Data in Transit
Tahmini Süre:1m 0s
Bu soruyu puanla