Which of the following is correct in regards to those s…

A government client needs you to set up secure cryptographic key storage for some of their
extremely confidential data. You decide that the AWS CloudHSM is the best service for this.

However, there seem to be a few pre-requisites before this can happen, one of those being a
security group that has certain ports open. Which of the following is correct in regards to those
security groups?

A government client needs you to set up secure cryptographic key storage for some of their
extremely confidential data. You decide that the AWS CloudHSM is the best service for this.

However, there seem to be a few pre-requisites before this can happen, one of those being a
security group that has certain ports open. Which of the following is correct in regards to those
security groups?

A.
A security group that has no ports open to your network.

B.
A security group that has only port 3389 (for RDP) open to your network.

C.
A security group that has only port 22 (for SSH) open to your network.

D.
A security group that has port 22 (for SSH) or port 3389 (for RDP) open to your network.

Explanation:
AWS CloudHSM provides secure cryptographic key storage to customers by making hardware
security modules (HSMs) available in the AWS cloud.
AWS CloudHSM requires the following environment before an HSM appliance can be
provisioned. A virtual private cloud (VPC) in the region where you want the AWS CloudHSM
service. One private subnet (a subnet with no Internet gateway) in the VPC. The HSM appliance
is provisioned into this subnet.
One public subnet (a subnet with an Internet gateway attached). The control instances are
attached to this subnet.
An AWS Identity and Access Management (IAM) role that delegates access to your AWS
resources to AWS CloudHSM.
An EC2 instance, in the same VPC as the HSM appliance, that has the SafeNet client software
installed. This instance is referred to as the control instance and is used to connect to and
manage the HSM appliance.
A security group that has port 22 (for SSH) or port 3389 (for RDP) open to your network. This
security group is attached to your control instances so you can access them remotely.



Leave a Reply 3

Your email address will not be published. Required fields are marked *


Otto

Otto

I think it is C.
The user guide has no information on a requirement for port 3389 to be opened. It does require port 22 though.
https://docs.aws.amazon.com/cloudhsm/latest/userguide/cloudhsm-user-guide.pdf

James

James

I agree, but not for Classic CloudHSM. In CloudHSM Classic as so called, it does require port 22 and 3389 (RDP) open. It looks to me both management and regular communications have to go through this single port 22.