AWS is responsible for the physical security of the facilities and infrastructure that make up AWS Regions and Availability Zones. AWS also operates the infrastructure, operating system, and service platform for abstracted managed services such as Amazon S3. Consequently, AWS is responsible for patching the underlying operating system and platform that run S3. Options D and E are therefore correct. Customers are responsible for managing and protecting their data, including deciding whether client-side encryption is needed and implementing appropriate encryption and integrity controls. Customers also use AWS Identity and Access Management tools to define their users, roles, policies, and permissions. Although AWS operates the IAM service itself, the customer is responsible for configuring identities and access to the customer’s resources. The phrase “manage customer data” is also a customer responsibility because AWS does not determine the customer’s data classification, retention, permissions, or business use. Responsibility changes according to the selected service, but physical infrastructure always remains an AWS responsibility in standard AWS Regions, while S3’s abstracted platform and operating-system layer are also managed by AWS.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit