A healthcare startup is migrating its patient records database to Amazon RDS for PostgreSQL. The company must comply with HIPAA and ensure that all protected health information (PHI) is encrypted at rest and in transit. Which task is the company responsible for under the AWS shared responsibility model?
Trap 1: Encrypting the physical disk drives in the AWS data center that…
The shared responsibility model assigns AWS full responsibility for physical data center security, including the encryption and destruction of physical disk drives. A healthcare startup cannot directly encrypt AWS's physical infrastructure, as it never controls or accesses the underlying hardware. This option describes a provider-side safeguard, not a customer action, so it fails to satisfy the security measure the startup must implement in the exam scenario.
Trap 2: Applying operating system patches to the Amazon RDS database engine.
In Amazon RDS, the managed service model places responsibility for applying operating system and database engine patches on AWS. The customer cannot perform these patching operations because they lack SSH access or OS-level control to RDS instances. Moreover, patching is a maintenance activity, not an encryption control, so it does not address the requirement for encrypting data at rest and in transit.
Trap 3: Configuring network ACLs to block all traffic except from…
Configuring network ACLs is indeed a customer responsibility and helps restrict traffic at the subnet boundary, but network ACLs are a network-layer access control mechanism, not a data encryption mechanism. They do not encrypt patient records stored in the RDS database or protect data in transit with SSL/TLS. Thus, this action would not meet the specific encryption-at-rest and in-transit requirements stated in the question.
- A
Encrypting the physical disk drives in the AWS data center that host the database.
Why it fails: The shared responsibility model assigns AWS full responsibility for physical data center security, including the encryption and destruction of physical disk drives. A healthcare startup cannot directly encrypt AWS's physical infrastructure, as it never controls or accesses the underlying hardware. This option describes a provider-side safeguard, not a customer action, so it fails to satisfy the security measure the startup must implement in the exam scenario.
- B
Enabling encryption at rest for the Amazon RDS instance and configuring SSL for connections.
This is the customer's responsibility. The customer must choose to enable encryption at rest when creating or modifying the RDS instance and must configure SSL/TLS settings to ensure data in transit is encrypted. AWS provides the underlying infrastructure, but the customer controls the encryption settings.
- C
Applying operating system patches to the Amazon RDS database engine.
Why it fails: In Amazon RDS, the managed service model places responsibility for applying operating system and database engine patches on AWS. The customer cannot perform these patching operations because they lack SSH access or OS-level control to RDS instances. Moreover, patching is a maintenance activity, not an encryption control, so it does not address the requirement for encrypting data at rest and in transit.
- D
Configuring network ACLs to block all traffic except from authorized sources.
Why it fails: Configuring network ACLs is indeed a customer responsibility and helps restrict traffic at the subnet boundary, but network ACLs are a network-layer access control mechanism, not a data encryption mechanism. They do not encrypt patient records stored in the RDS database or protect data in transit with SSL/TLS. Thus, this action would not meet the specific encryption-at-rest and in-transit requirements stated in the question.