Soru

Zorluk: KolayData Protection and Encryption

A financial institution is migrating its payment transaction database to AWS. Due to strict regulatory compliance requirements, the institution must manage and control its cryptographic keys using dedicated, single-tenant hardware security modules (HSMs) directly within their Virtual Private Cloud (VPC). Which AWS service should the institution use to meet this requirement?

  1. A
    AWS Key Management Service (AWS KMS)
  2. AWS CloudHSMCevap
  3. C
    AWS Artifact
  4. D
    AWS Shield

Cevap

AWS CloudHSM
AWS CloudHSM is the correct service because it provides dedicated, single-tenant hardware security modules (HSMs) running in the customer's Virtual Private Cloud (VPC). This allows the customer to have complete control over key management, encryption, and cryptographic operations, satisfying the strict regulatory compliance requirement.

Adım Adım Çözüm

1
Analyze the customer's encryption and key storage requirements.
The customer requires dedicated, single-tenant hardware security modules (HSMs) that they manage directly.
This is a regulatory compliance constraint that rules out shared or multi-tenant managed key services.
2
Identify the AWS service that provides dedicated HSMs.
AWS CloudHSM is the service that provisions dedicated, single-tenant HSM instances inside the customer's VPC.
AWS CloudHSM gives the customer exclusive control over key storage hardware, satisfying the compliance requirement.

Anahtar Kavram

Dedicated key management using AWS CloudHSM versus multi-tenant key management using AWS KMS.
Bu soruyu puanla