ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 38 - DVA-C01 discussion

Report
Export

In AWS, which security aspects are the customer’s responsibility? Choose 4 answers

A.
Life-cycle management of IAM credentials
Answers
A.
Life-cycle management of IAM credentials
B.
Decommissioning storage devices
Answers
B.
Decommissioning storage devices
C.
Security Group and ACL (Access Control List) settings
Answers
C.
Security Group and ACL (Access Control List) settings
D.
Encryption of EBS (Elastic Block Storage) volumes
Answers
D.
Encryption of EBS (Elastic Block Storage) volumes
E.
Controlling physical access to compute resources
Answers
E.
Controlling physical access to compute resources
F.
Patch management on the EC2 instance’s operating system
Answers
F.
Patch management on the EC2 instance’s operating system
Suggested answer: A, C, D, F

Explanation:

Physical and Environmental Security

AWS’s data centers are state of the art, utilizing innovative architectural and engineering approaches. Amazon has many years of experience in designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. Storage Decommissioning

When a storage device has reached the end of its useful life, AWS procedures include a decommissioning process that is designed to prevent customer data from being exposed to unauthorized individuals. AWS uses the techniques detailed in DoD 5220.22-M (National Industrial Security Program Operating Manual) or NIST 800-88 (Guidelines for Media Sanitization) to destroy data as part of the decommissioning process. All decommissioned magnetic storage devices are degaussed and physically destroyed in accordance with industry-standard practices.

asked 16/09/2024
David Codrington
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first