Soru

Zorluk: OrtaShared Responsibility Model

A media streaming startup deploys its backend APIs using AWS Lambda. Under the AWS Shared Responsibility Model, which of the following operational tasks is the responsibility of the startup?

  1. A
    Patching and upgrading the operating system of the underlying containers.
  2. Configuring the IAM execution role to restrict the function's access to other AWS resources.Cevap
  3. C
    Maintaining the physical security of the hardware host servers running the Lambda environments.
  4. D
    Managing the virtualization hypervisor layer that isolates concurrent executions.

Cevap

Configuring the IAM execution role to restrict the function's access to other AWS resources.
Configuring the IAM execution role is the customer's responsibility. Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud, which includes data classification, identity and access management (IAM), and the configuration of code and permissions. AWS Lambda is a serverless (PaaS) service, so AWS manages the underlying physical infrastructure, virtualization hypervisor, operating system, and runtime environments.

Adım Adım Çözüm

1
Identify the service model and the service type referenced in the scenario.
The scenario involves AWS Lambda, which is a serverless / Platform as a Service (PaaS) offering.
The division of responsibilities depends on the type of service being used (IaaS, PaaS, or SaaS).
2
Distinguish between the customer's responsibility (security 'in' the cloud) and AWS's responsibility (security 'of' the cloud) for serverless services.
For serverless services, AWS manages the physical security, hardware, hypervisor, OS, and runtime. The customer is responsible for configurations, code, data, and access control (IAM).
This boundary defines which tasks must be performed by the customer and which are handled automatically by AWS.
3
Evaluate the options to find the task that falls under the customer's responsibility.
Configuring the IAM execution role is an access control configuration task and is the customer's responsibility.
This confirms the correct option based on the defined boundary.

Anahtar Kavram

AWS Shared Responsibility Model for Serverless Services
Tahmini Süre:1m 0s
Bu soruyu puanla