Not C : Design encryption-at-rest strategies:
Amazon RDS offers encryption-at-rest for database storage by default. It handles the encryption of data on disk and manages the associated keys. As a customer, you can enable encryption when creating an Amazon RDS instance, but you don't need to design the encryption strategy yourself.
Not 'A', because the RDS service manages database connections.
'C' is correct because RDS doesn't automatically set up encryption-at-rest. The customer has to choose whether to enable it via the console or pass the appropriate parameters when using the CLI or an API to create the DB. That's the strategy the customer is responsible for in the Shared Responsibility Model.
Think about it another way. Amazon isn't going to come along someday and decrypt a customer's database, so it can't be something they manage.
C. Design encryption-at-rest strategies
Explanation:
The customer's responsibility is to design encryption-at-rest strategies. This involves configuring encryption for data stored in the RDS database, ensuring sensitive data is protected from unauthorized access to the underlying storage. While Amazon RDS manages infrastructure, including hardware provisioning, database setup, patching, and backups, customers must take proactive steps to safeguard their data by designing and implementing encryption strategies based on their security and compliance needs.
This would be C as per 'Shared Responsibility Model' customer is responsible for security 'in the cloud'. Though AWS provides encryption methods, activating it and using it properly is customers responsibility.
To me, this became obvious once I stripped away the technical aspect of the question and just asked myself, would I, as a customer, want AWS to manage connections to my database? The answer is A.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
vadiminski_a
Highly Voted 2 years, 3 months agoSO_CH
Highly Voted 1 year, 8 months agoguilherme_tambelini
Most Recent 3 weeks, 2 days agosonaljain
1 month, 1 week agoKaal97
1 month, 1 week agoDipa_2910
5 days, 1 hour agoIma_learner
11 months, 1 week agohar_new
12 months agoJames_Srm
1 year agoManikRoy
1 year agoRangilaThakur
1 year, 1 month agolionardo005684431535
1 year, 1 month agoohoong
1 year, 1 month agotechandra
1 year, 2 months agomed_dernoun
1 year, 3 months agoisaphiltrick
1 year, 4 months agoblopa
1 year, 5 months agoPranava_GCP
1 year, 6 months ago