An online travel agency is migrating its booking application to AWS. The agency must ensure that customer passport numbers are encrypted at rest using encryption keys managed by the customer, and that database backups are securely stored. Under the AWS shared responsibility model, which of the following are responsibilities of the customer for protecting this data? (Select TWO.)
- Defining key policies and rotation schedules for Customer Managed Keys (CMKs) in AWS Key Management Service (AWS KMS)Cevap
- Enabling server-side encryption on the storage services used for storing database backupsCevap
- CManaging the physical security and climate controls of the data centers housing the hardware security modules (HSMs)
- DPerforming hardware decommissioning and safe disposal of retired physical storage media containing backup data
- EConfiguring a dedicated AWS CloudHSM cluster to host and store standard AWS-managed KMS keys
Cevap
The customer is responsible for defining key policies and rotation schedules for Customer Managed Keys (CMKs) in AWS KMS, and enabling server-side encryption on the storage services used for storing database backups.
Under the AWS shared responsibility model, the customer is responsible for security 'in' the cloud, which includes configuring data encryption at rest (such as enabling server-side encryption on backup storage) and managing key access policies and rotation schedules for Customer Managed Keys (CMKs) within AWS Key Management Service (AWS KMS).
Adım Adım Çözüm
Anahtar Kavram
AWS Shared Responsibility Model for Data Encryption and Key Management