EBS 3 Flashcards
Sanitisation
What happens to the data on your EBS volume when you destroy your disk?
Nothing! Stays in-place on raw disks.
Sanitisation
How does AWS prevent your raw data from being exposed to next EBS volume created?
AWS wipes disk blocks before providing to a new EBS volume.
Sanitisation
How can you wipe your data before unallocating an EBS volume?
Manually from inside EC2, use EBS encryption.
Sanitisation
Why does EBS encryption assure your data doesn’t exist after unallocate an EBS volume?
It doesn’t, but the DEK is only accessible from your account, so data is effectively wiped.
Sanitisation
What happens to your data when AWS decommissions physical volumes?
AWS destroys data conforming to DoD and NIST guidelines.