A tourism agency is deploying a customer-facing mobile booking application and decides to use Amazon Cognito for user authentication and directory management. Under the AWS Shared Responsibility Model, which of the following is a responsibility of the customer?
- AApplying security updates and OS patches to the physical servers hosting the Cognito authentication endpoints
- BConfiguring Network Access Control Lists (NACLs) at the subnet level to restrict network traffic directly to the Cognito user pool
- Configuring password complexity policies and enabling Multi-Factor Authentication (MFA) for the Cognito user poolsCevap
- DSubmitting a technical support ticket to request the latest ISO and PCI DSS compliance reports for AWS infrastructure
Cevap
Configuring password complexity policies and enabling Multi-Factor Authentication (MFA) for the Cognito user pools
Under the AWS Shared Responsibility Model, configuring identity settings (such as password policies and MFA requirements) represents security 'in' the cloud, which is the customer's responsibility.
Adım Adım Çözüm
Anahtar Kavram
Under the AWS Shared Responsibility Model, for managed services like Amazon Cognito, AWS is responsible for physical security and server/infrastructure maintenance, while the customer is responsible for service configuration, data classification, and access policies.
Tahmini Süre:1m 0s