๐Ÿ” Domain 1-3: Determine Appropriate Data Security Controls

โœจ ํ•ต์‹ฌ ์ฃผ์ œ

  • ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ(Data Protection) ๋Š” AWS ๋ณด์•ˆ ์„ค๊ณ„์˜ ์ค‘์‹ฌ
  • ๋ฐ์ดํ„ฐ๋Š” ์ €์žฅ ์‹œ(At Rest) ์™€ ์ „์†ก ์ค‘(In Transit) ๋ชจ๋‘ ์•”ํ˜ธํ™” ํ•„์š”
  • ์ตœ์†Œ ๊ถŒํ•œ ์›์น™(Least Privilege)๊ณผ ํ‚ค ๊ด€๋ฆฌ๊ฐ€ ํ•ต์‹ฌ

๐Ÿงฑ ์•”ํ˜ธํ™” Fundamentals

  • ์•”ํ˜ธํ™” ์œ ํ˜•
    • At Rest: ์ €์žฅ ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ (S3, EBS, RDS ๋“ฑ)
    • In Transit: ์ „์†ก ์ค‘ ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ (TLS/SSL, ACM ์ธ์ฆ์„œ)
  • ์šฉ์–ด
    • Plaintext: ์•”ํ˜ธํ™” ์ „ ๋ฐ์ดํ„ฐ (๋ฌธ์„œ, ์ด๋ฏธ์ง€, ์•ฑ ๋“ฑ)
    • Algorithm: ์•”ํ˜ธํ™” ์ฒ˜๋ฆฌ ๋กœ์ง
    • Key: ์•”ํ˜ธํ™”/๋ณตํ˜ธํ™” ๋น„๋ฐ€ (๋Œ€์นญ/๋น„๋Œ€์นญ)
    • Ciphertext: ์•”ํ˜ธํ™”๋œ ๋ฐ์ดํ„ฐ
  • ์•”ํ˜ธํ™” ํ‚ค
    • ๋Œ€์นญํ‚ค (Symmetric): ํ•˜๋‚˜์˜ ํ‚ค๋กœ ์•”ํ˜ธํ™”·๋ณตํ˜ธํ™”
    • ๋น„๋Œ€์นญํ‚ค (Asymmetric): ๊ณต๊ฐœํ‚ค/๊ฐœ์ธํ‚ค ๋ถ„๋ฆฌ

๐Ÿ”‘ AWS ์•”ํ˜ธํ™” ์„œ๋น„์Šค

  • KMS (Key Management Service)
    • Managed key ๊ด€๋ฆฌ, ์ž๋™ ํšŒ์ „ ์ง€์›
    • ํ†ตํ•ฉ ์„œ๋น„์Šค ๋งŽ์Œ (EBS, S3, RDS, Lambda ๋“ฑ)
  • CloudHSM
    • ๊ณ ๊ฐ ์ „์šฉ HSM(Hardware Security Module)
    • ๊ทœ์ œ·๋ณด์•ˆ์„ฑ ๋†’์€ ํ™˜๊ฒฝ์—์„œ ์‚ฌ์šฉ
  • KMS + CloudHSM → ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํ‚ค ๊ด€๋ฆฌ ๊ฐ€๋Šฅ
  • AWS Certificate Manager (ACM)
    • SSL/TLS ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ๋ฐ ์ž๋™ ๊ฐฑ์‹ 
  • S3 ์•”ํ˜ธํ™”
    • Client-side Encryption (ํด๋ผ์ด์–ธํŠธ์—์„œ ์•”ํ˜ธํ™” ํ›„ ์—…๋กœ๋“œ)
    • Server-side Encryption (SSE)
      • SSE-S3: S3 ๊ด€๋ฆฌ ํ‚ค
      • SSE-KMS: KMS ํ‚ค
      • SSE-C: ๊ณ ๊ฐ ์ œ๊ณต ํ‚ค

๐Ÿ“‹ ๋ฐ์ดํ„ฐ ๋ณด์•ˆ & ์ปดํ”Œ๋ผ์ด์–ธ์Šค

  • ๊ณต์œ  ์ฑ…์ž„ ๋ชจ๋ธ: AWS(์ธํ”„๋ผ ๋ณด์•ˆ) + ๊ณ ๊ฐ(๋ฐ์ดํ„ฐ/์ ‘๊ทผ ๊ด€๋ฆฌ)
  • AWS Artifact: ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ณด๊ณ ์„œ/์ธ์ฆ์„œ ํ™•์ธ
  • Cloud Adoption Framework (CAF) – Security Perspective
    • IAM
    • Detective Controls
    • Infrastructure Security
    • Data Protection
    • Incident Response

๐Ÿ›ก ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ ํŒจํ„ด

  • ๋ฐฉ์–ด ์‹ฌ์ธต(Defense in Depth) → ์˜ˆ๋ฐฉ(Preventive) + ํƒ์ง€(Detective)
  • ๋ฐ์ดํ„ฐ ๋ถ„๋ฅ˜ → ๋ฏผ๊ฐ๋„์— ๋”ฐ๋ฅธ ๋ณด์•ˆ ์ •์ฑ… ์ ์šฉ
  • ์ ‘๊ทผ ํŒจํ„ด ๊ธฐ๋ฐ˜ ์ œ์–ด → S3 ๋ฒ„ํ‚ท/๊ฐ์ฒด ๋‹จ์œ„ ์ •์ฑ…, Lifecycle ๊ด€๋ฆฌ

๐Ÿ’พ ์Šคํ† ๋ฆฌ์ง€ ๋ณด์•ˆ & DR

  • ์Šคํ† ๋ฆฌ์ง€ ์œ ํ˜•: Object(S3), File(EFS), Block(EBS)
  • ํ™œ์šฉ ์‚ฌ๋ก€: Backup/Recovery, Migration, Compliance, Data Lakes
  • DR ์ „๋žต (Disaster Recovery)
    1. Backup & Restore (์ €๋น„์šฉ, ๊ธฐ๋ณธ DR)
    2. Pilot Light (์ตœ์†Œ ํ•ต์‹ฌ๋งŒ ์œ ์ง€, ํ•„์š” ์‹œ ํ™•์žฅ)
    3. Warm Standby (์ถ•์†Œ ๋ฒ„์ „ ์šด์˜, ์žฅ์•  ์‹œ ํ™•์žฅ)
    4. Multi-site Active-Active (๊ณ ๋น„์šฉ, ๊ณ ๊ฐ€์šฉ์„ฑ)
  • AWS Backup (์ค‘์•™ ๊ด€๋ฆฌ)
    • ์ง€์›: EBS, EC2, RDS, Aurora, DynamoDB, EFS, Storage Gateway, FSx
    • ํฌ๋กœ์Šค ๋ฆฌ์ „ ๋ฐฑ์—…, ๋ณต๊ตฌ ์‹œ์  ์„ ํƒ ์ง€์›
  • ์Šค๋ƒ…์ƒท/๋ณต์ œ ๊ธฐ๋Šฅ
    • EBS Snapshot
    • RDS/Aurora Snapshot
    • DynamoDB Backup
    • S3 Cross-Region Replication (๋ฒ„์ „ ๊ด€๋ฆฌ ํฌํ•จ)
  • Hybrid ํ™˜๊ฒฝAWS Storage Gateway

๐Ÿ“Š ์‹œํ—˜ ๋Œ€๋น„ ํ•ต์‹ฌ ๋น„๊ต

  • KMS vs CloudHSM → ๊ด€๋ฆฌํ˜• vs ์ „์šฉ HSM
  • S3 ์•”ํ˜ธํ™” ๋ฐฉ์‹ → SSE-S3 / SSE-KMS / SSE-C / Client-side
  • Secrets Manager vs Parameter Store (์ด์ „ Task Statement ์—ฐ๊ฒฐ)
  • DR ์ „๋žต 4๋‹จ๊ณ„ → Backup→Pilot Light→Warm Standby→Multi-site
  • ๋ฐ์ดํ„ฐ ์„ฑ๋Šฅ ์˜ํ–ฅ → KMS/RDS ์ผ๋ถ€ ์„ฑ๋Šฅ ์˜ํ–ฅ ๊ฐ€๋Šฅ, EBS ์•”ํ˜ธํ™” ์˜ํ–ฅ ๋ฏธ๋ฏธ

๐Ÿ“Š ์‹œ๊ฐํ™” ๋‹ค์ด์–ด๊ทธ๋žจ

 
flowchart TD A[Data Security Controls] A --> B[Encryption] B --> B1[At Rest] B --> B2[In Transit] B --> B3[Symmetric / Asymmetric] B --> B4[KMS vs CloudHSM] B --> B5[S3 SSE-S3 / SSE-KMS / SSE-C / Client-side] A --> C[Compliance] C --> C1[AWS Artifact] C --> C2[CAF - Security Perspective] A --> D[Storage & DR] D --> D1[Backup & Restore] D --> D2[Pilot Light] D --> D3[Warm Standby] D --> D4[Multi-site Active-Active] D --> D5[AWS Backup / Snapshots / Replication] A --> E[Access & Patterns] E --> E1[Least Privilege] E --> E2[Data Classification] E --> E3[Defense in Depth] E --> E4[S3 Lifecycle / Intelligent Tiering]

โœ… ์ •๋ฆฌ

  • ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ๋Š” At Rest + In Transit ์•”ํ˜ธํ™”๊ฐ€ ๊ธฐ๋ณธ
  • KMS, CloudHSM, ACM, S3 Encryption ๋ฐฉ์‹ ์ˆ™์ง€
  • AWS Artifact์™€ CAF Security ๊ด€์  ์ดํ•ด
  • DR ์ „๋žต(Backup → Active-Active) ์•”๊ธฐ ํ•„์ˆ˜
  • AWS Backup, Snapshots, Replication ์„œ๋น„์Šค ํ™œ์šฉ๋ฒ• ์ˆ™์ง€

'AWS > AWS SAA-C03' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[AWS SAA-C03] - Domain 1 Review_ 2.Design Secure Workloads and Applications  (0) 2025.08.30
[AWS SAA-C03] - Domain 1 Review_ 1. Introduction  (0) 2025.08.30

+ Recent posts