Soru

Zorluk: ZorData Protection and Encryption

A media streaming platform is implementing a security policy to protect user payment information and video assets on AWS. The security team needs to configure encryption for data at rest in Amazon S3 and data in transit between users and the streaming application. Which of the following statements represent the customer's responsibility under the AWS Shared Responsibility Model for this data protection scenario? (Select TWO.)

  1. Configuring key policies in AWS Key Management Service (AWS KMS) to restrict access to encryption keysCevap
  2. Enabling HTTPS on the application's load balancers by installing SSL/TLS certificatesCevap
  3. C
    Replacing failed physical storage drives that hold encrypted Amazon S3 objects
  4. D
    Upgrading the underlying firmware of the hardware security modules (HSMs) used by AWS KMS
  5. E
    Deploying dedicated physical cryptographic hardware in the AWS data center to store S3 encryption keys

Cevap

Configuring key policies in AWS Key Management Service (AWS KMS) to restrict access to encryption keys, and enabling HTTPS on the application's load balancers by installing SSL/TLS certificates.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in the cloud.' In this scenario, this includes managing access controls to their cryptographic resources (such as configuring key policies in AWS KMS) and securing data in transit (such as enabling HTTPS and installing SSL/TLS certificates on the load balancers they deploy). AWS is responsible for security 'of the cloud,' which covers physical infrastructure security, physical host maintenance, and operating system/firmware patching of managed services.

Adım Adım Çözüm

1
Determine the scope of the customer's control over encryption at rest within S3.
The customer is responsible for configuring S3 bucket settings and defining who can use the encryption keys by creating and managing KMS key policies.
Security 'in the cloud' dictates that the customer manages their data configurations and access controls.
2
Determine the scope of the customer's control over encryption in transit.
The customer must secure transport layer traffic by obtaining SSL/TLS certificates and configuring endpoints, such as load balancers, to require HTTPS.
AWS does not automatically enforce transit encryption on customer-managed endpoints; this configuration is the customer's responsibility.
3
Identify and eliminate AWS infrastructure responsibilities.
Tasks involving physical hardware replacement, physical data center operations, and managed service firmware upgrades are classified as security 'of the cloud' and belong to AWS.
AWS handles all operational, physical, and foundational maintenance of cloud infrastructure.

Anahtar Kavram

Shared Responsibility Model for Data Protection and Encryption
Bu soruyu puanla