Soru

Zorluk: KolayShared Responsibility Model

A financial services company uses an Amazon Simple Storage Service (Amazon S3) bucket to store sensitive customer account statements. Which of the following tasks are the responsibility of the customer under the AWS Shared Responsibility Model? (Select TWO.)

  1. Configuring S3 bucket policies to restrict access to authorized usersCevap
  2. Enabling server-side encryption for objects uploaded to the bucketCevap
  3. C
    Replacing faulty physical disk drives within the AWS data centers
  4. D
    Patching and upgrading the operating systems running the S3 storage nodes
  5. E
    Managing physical access controls for the facilities hosting the storage infrastructure

Cevap

Configuring S3 bucket policies to restrict access to authorized users and enabling server-side encryption for objects uploaded to the bucket are customer responsibilities.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. For a managed service like Amazon S3, this includes managing data access permissions (such as bucket policies) and configuring encryption settings (such as server-side encryption). AWS is responsible for security 'of' the cloud, which includes the physical infrastructure and the underlying software platform.

Adım Adım Çözüm

1
Analyze the service type in the scenario.
Amazon S3 is a fully managed object storage service.
For managed services, AWS handles the infrastructure, physical security, and underlying operating systems, while the customer manages data classification, access permissions, and encryption settings.
2
Evaluate the customer-side responsibilities (security 'in' the cloud) for S3.
Configuring bucket policies and enabling server-side encryption are operations performed by the customer on their own data.
These controls determine who can access the objects and whether the data is encrypted at rest, which are customer responsibilities.
3
Evaluate the AWS-side responsibilities (security 'of' the cloud) for S3.
Managing physical drives, patching the storage node operating systems, and data center physical security are handled by AWS.
These tasks involve physical infrastructure and the virtualization/management layer of the storage service, which are fully managed by AWS.

Anahtar Kavram

Shared Responsibility Model for Managed Services
Bu soruyu puanla