Soru

Zorluk: KolayShared Responsibility Model

A company is configuring network security for an Amazon EC2 instance. The administrator wants to apply stateful firewall rules directly to the instance. Under the AWS Shared Responsibility Model, which of the following is the customer's responsibility to configure to meet this requirement?

  1. Security groupsCevap
  2. B
    Network Access Control Lists (NACLs)
  3. C
    Physical firewalls at the data center boundary
  4. D
    AWS Artifact compliance documents

Cevap

Security groups
The correct option is 'Security groups' because security groups are stateful firewalls that control inbound and outbound traffic at the instance level. Under the AWS Shared Responsibility Model, configuring security groups is the responsibility of the customer.

Adım Adım Çözüm

1
Identify the resource and security requirement in the scenario.
The resource is an Amazon EC2 instance, which is an Infrastructure as a Service (IaaS) resource, and the requirement is to apply stateful firewall rules directly to it.
This establishes the boundary of the Shared Responsibility Model (customer responsibility for guest OS and instance-level firewalls) and the specific technical constraints (stateful, instance-level).
2
Evaluate the options against the Shared Responsibility Model and technical requirements.
Security groups are stateful, operate at the instance level, and are configured by the customer. Network Access Control Lists (NACLs) operate at the subnet level and are stateless. Physical firewalls are managed entirely by AWS. AWS Artifact is a compliance reporting portal, not a firewall service.
This eliminates the incorrect options based on their operational level (instance vs. subnet vs. physical infrastructure) and statefulness.

Anahtar Kavram

Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud, which includes configuring instance-level, stateful firewalls (security groups) for Amazon EC2 instances.
Bu soruyu puanla