Soru

Zorluk: OrtaData Protection and Encryption

An online travel agency is migrating its booking application to AWS. The agency must ensure that customer passport numbers are encrypted at rest using encryption keys managed by the customer, and that database backups are securely stored. Under the AWS shared responsibility model, which of the following are responsibilities of the customer for protecting this data? (Select TWO.)

  1. Defining key policies and rotation schedules for Customer Managed Keys (CMKs) in AWS Key Management Service (AWS KMS)Cevap
  2. Enabling server-side encryption on the storage services used for storing database backupsCevap
  3. C
    Managing the physical security and climate controls of the data centers housing the hardware security modules (HSMs)
  4. D
    Performing hardware decommissioning and safe disposal of retired physical storage media containing backup data
  5. E
    Configuring a dedicated AWS CloudHSM cluster to host and store standard AWS-managed KMS keys

Cevap

The customer is responsible for defining key policies and rotation schedules for Customer Managed Keys (CMKs) in AWS KMS, and enabling server-side encryption on the storage services used for storing database backups.
Under the AWS shared responsibility model, the customer is responsible for security 'in' the cloud, which includes configuring data encryption at rest (such as enabling server-side encryption on backup storage) and managing key access policies and rotation schedules for Customer Managed Keys (CMKs) within AWS Key Management Service (AWS KMS).

Adım Adım Çözüm

1
Differentiate between customer responsibilities (security 'in' the cloud) and AWS responsibilities (security 'of' the cloud) regarding data protection.
Identify that managing key configurations and enabling encryption settings on storage services are customer duties, whereas physical security and hardware retirement are AWS duties.
To classify each option according to the AWS Shared Responsibility Model.
2
Evaluate the management boundaries of AWS KMS key types and AWS CloudHSM.
Determine that standard AWS-managed keys cannot be managed within a dedicated AWS CloudHSM cluster, which is a single-tenant hardware solution.
To eliminate incorrect options regarding key management infrastructure integrations.

Anahtar Kavram

AWS Shared Responsibility Model for Data Encryption and Key Management
Bu soruyu puanla