ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 175 - CLF-C02 discussion

Report
Export

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

A.
Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)
Answers
A.
Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)
B.
Server-side encryption with AWS KMSmanaged keys (SSE-KMS)
Answers
B.
Server-side encryption with AWS KMSmanaged keys (SSE-KMS)
C.
TLS
Answers
C.
TLS
D.
SSL
Answers
D.
SSL
E.
Transparent Data Encryption (TDE)
Answers
E.
Transparent Data Encryption (TDE)
Suggested answer: A, B

Explanation:

Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) and server-side encryption with AWS KMS managed keys (SSE-KMS) are the encryption types that can be used to protect objects at rest in Amazon S3. Server-side encryption means that Amazon S3 encrypts the objects before saving them on disks and decrypts them when they are downloaded. SSE-S3 uses one master key per bucket that is managed by Amazon S3. SSE-KMS uses a customer master key (CMK) that is stored in AWS Key Management Service (AWS KMS) and provides additional benefits, such as audit trails and key rotation. For more information, see Protecting Data Using Server-Side Encryption and Protecting Data Using Encryption.

asked 16/09/2024
Marcos Antonio Dantas
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first