ฝ่ายความมั่นคงตรวจ configuration กรณี 119 สำหรับคลังเอกสาร ที่ศูนย์สำรอง พบโปรไฟล์ capacity เต็ม failover ไม่ผ่าน ประเด็น “Cloud และ shared responsibility” แนวทางใดแก้สาเหตุได้เหมาะสมที่สุด

เปิด storage สาธารณะเพื่อแก้ permission
ทำ responsibility matrix คุม identity configuration encryption logging backup และ recovery
ไม่ต้องสำรองเพราะระบบอยู่หลายศูนย์ข้อมูล
ถือผู้ให้บริการรับผิดชอบรหัสผ่านผู้ใช้ทั้งหมด

เฉลยอธิบาย

บริการ cloud ลดภาระบางชั้นแต่ผู้ใช้ยังรับผิดชอบข้อมูล ตัวตน การกำหนดค่า และ workload ตาม service model; การอยู่บน cloud ไม่ทำให้ปลอดภัยหรือสำรองโดยอัตโนมัติ จึงเลือกข้อ B อ้างอิงมาตรฐานและเอกสารทางการปัจจุบัน ได้แก่ RFC Editor สำหรับ TCP/IP และ IPv6 https://www.rfc-editor.org/ NIST SP 800-207 เรื่อง Zero Trust https://www.nist.gov/publications/zero-trust-architecture เอกสาร Hyper-V/Windows Server รุ่นที่รองรับปัจจุบัน https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/overview และคำอธิบาย virtual network, VLAN และ overlay https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/understanding-usage-of-virtual-networks-and-vlans

ข้อสอบอื่นในวิชาระบบเครือข่ายคอมพิวเตอร์ (Network Computer) ระบบปฏิบัติการ (Operating System) คลาวด์ และ Virtualization (Cloud & Virtualization)

ดูข้อสอบวิชานี้ทั้งหมด →