Not C : Design encryption-at-rest strategies:
Amazon RDS offers encryption-at-rest for database storage by default. It handles the encryption of data on disk and manages the associated keys. As a customer, you can enable encryption when creating an Amazon RDS instance, but you don't need to design the encryption strategy yourself.
Since this is single option, While managing connections (A) is a customer task, encryption-at-rest strategies directly involve data security, a critical customer responsibility under the shared model. AWS RDS provides encryption tools, but customers must enable it.
Not 'A', because the RDS service manages database connections.
'C' is correct because RDS doesn't automatically set up encryption-at-rest. The customer has to choose whether to enable it via the console or pass the appropriate parameters when using the CLI or an API to create the DB. That's the strategy the customer is responsible for in the Shared Responsibility Model.
Think about it another way. Amazon isn't going to come along someday and decrypt a customer's database, so it can't be something they manage.
C. Design encryption-at-rest strategies
Explanation:
The customer's responsibility is to design encryption-at-rest strategies. This involves configuring encryption for data stored in the RDS database, ensuring sensitive data is protected from unauthorized access to the underlying storage. While Amazon RDS manages infrastructure, including hardware provisioning, database setup, patching, and backups, customers must take proactive steps to safeguard their data by designing and implementing encryption strategies based on their security and compliance needs.
This would be C as per 'Shared Responsibility Model' customer is responsible for security 'in the cloud'. Though AWS provides encryption methods, activating it and using it properly is customers responsibility.
To me, this became obvious once I stripped away the technical aspect of the question and just asked myself, would I, as a customer, want AWS to manage connections to my database? The answer is A.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
vadiminski_a
Highly Voted 2 years, 6 months agoSO_CH
Highly Voted 1 year, 10 months agoatom
Most Recent 2 months, 2 weeks agoguilherme_tambelini
3 months, 2 weeks agosonaljain
4 months agoKaal97
4 months agoDipa_2910
2 months, 3 weeks agoIma_learner
1 year, 1 month agohar_new
1 year, 2 months agoJames_Srm
1 year, 3 months agoManikRoy
1 year, 3 months agoRangilaThakur
1 year, 3 months agolionardo005684431535
1 year, 3 months agoohoong
1 year, 4 months agotechandra
1 year, 5 months agomed_dernoun
1 year, 6 months agoisaphiltrick
1 year, 6 months agoblopa
1 year, 8 months ago