AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium
A financial institution is migrating its applications to AWS and has strict requirements for data residency and isolation. They need to ensure that all data processed and stored by their applications remains within a specific geographic region and is logically separated from other customers' data within that region. Which AWS service and approach would BEST address these requirements?
- AUse AWS Outposts for on-premises data residency and AWS Identity and Access Management (IAM) for isolation.
- BDeploy applications on AWS Local Zones for data residency and use Amazon S3 bucket policies for isolation.
- CUtilize AWS Regions and Availability Zones to ensure data residency, and implement VPCs for logical isolation.
- DLeverage AWS Wavelength Zones for low-latency access and implement AWS Key Management Service (KMS) for data isolation.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize AWS Regions and Availability Zones to ensure data residency, and implement VPCs for logical isolation.
AWS Regions inherently provide data residency within a specific geographic area. Virtual Private Clouds (VPCs) are the fundamental networking construct in AWS for logically isolating customer resources and data from other customers and the public internet, fulfilling the isolation requirement.
Why the other options are wrong
- A. AWS Outposts provides on-premises data residency, but the question implies migration *to* AWS. IAM manages access, not network or data isolation itself.
- B. Local Zones extend AWS regions but don't define the primary data residency boundary; S3 policies provide access control, not comprehensive network isolation for an entire application.
- D. Wavelength Zones are for ultra-low latency at the edge, not primary data residency. KMS provides encryption, which contributes to security, but not logical data isolation for the application's network and compute resources.
AWS Region & VPC for Isolation
AWS Regions define geographical boundaries for data residency, while Virtual Private Clouds (VPCs) provide logically isolated network environments within a Region for customer resources.
- Regions are geographically distinct areas.
- VPCs are isolated networks, configurable by the user.
- Data within a Region generally stays within that Region.
Memory trick: Stay 'regional' and 'private' to keep data 'safe' and 'home'.