Soru

Zorluk: OrtaShared Responsibility Model

A financial services company uses Amazon Simple Storage Service (Amazon S3) to store sensitive customer transaction records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer responsible for performing?

  1. A
    Upgrading the operating systems and applying security patches to the physical servers hosting Amazon S3 buckets
  2. Configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, to restrict access to the stored transaction recordsCevap
  3. C
    Managing the physical security of the storage media and data centers where the bucket data is replicated
  4. D
    Obtaining and managing formal compliance certifications, such as SOC 2, for the underlying physical storage hardware infrastructure

Cevap

Configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, to restrict access to the stored transaction records
The task of configuring access controls, such as bucket policies and Identity and Access Management (IAM) policies, represents security 'in' the cloud. Because the customer owns the data stored in the S3 bucket, they are solely responsible for determining who can access that data and configuring the permissions accordingly.

Adım Adım Çözüm

1
Identify the AWS service type and its place in the Shared Responsibility Model.
Amazon S3 is a managed service (PaaS/storage service) where AWS manages the underlying infrastructure, operating systems, and physical security.
Understanding the service type determines where the boundary between customer and AWS responsibility lies.
2
Distinguish between security 'of' the cloud and security 'in' the cloud.
Security 'of' the cloud includes hardware, virtualization, and physical facilities, which AWS manages. Security 'in' the cloud includes customer data, access management, and resource configuration, which the customer manages.
This distinction allows mapping of operational tasks to the correct owner.
3
Evaluate the choices based on the determined boundaries.
Upgrading host OS, physical security, and obtaining infrastructure compliance certifications belong to AWS. Configuring bucket policies and IAM permissions is a customer configuration task to protect their own data.
Applying the model boundaries helps isolate the correct customer responsibility.

Anahtar Kavram

AWS Shared Responsibility Model for Managed Services (Amazon S3)
Bu soruyu puanla