An online education platform stores student grades and profile details on AWS. To comply with privacy standards, the platform must ensure that data is encrypted both at rest and in transit. Under the AWS shared responsibility model, which of the following actions are responsibilities of the customer? (Select TWO.)
- Configuring server-side encryption on Amazon S3 buckets used to store student filesCevap
- Managing SSL/TLS certificates and traffic encryption for application servers running on Amazon EC2Cevap
- CMaintaining physical security of the data centers housing the storage and encryption hardware
- DReplacing defective physical storage drives that hold encrypted data in AWS facilities
- EUsing AWS CloudHSM as the default multi-tenant service to automatically manage S3 bucket keys
Cevap
The correct responsibilities of the customer are configuring server-side encryption on Amazon S3 buckets and managing SSL/TLS certificates and traffic encryption on Amazon EC2 instances.
Under the AWS shared responsibility model, the customer is responsible for 'security in the cloud,' which includes managing data encryption options (such as enabling server-side encryption on Amazon S3) and configuring network traffic protection at the OS/application layer (such as SSL/TLS configuration on EC2 instances).
Adım Adım Çözüm
Anahtar Kavram
AWS Shared Responsibility Model for Data Protection and Encryption