ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - DAS-C01 discussion

Report
Export

A banking company is currently using an Amazon Redshift cluster with dense storage (DS) nodes to store sensitive data. An audit found that the cluster is unencrypted. Compliance requirements state that a database with sensitive data must be encrypted through a hardware security module (HSM) with automated key rotation. Which combination of steps is required to achieve compliance? (Choose two.)

A.
Set up a trusted connection with HSM using a client and server certificate with automatic key rotation.
Answers
A.
Set up a trusted connection with HSM using a client and server certificate with automatic key rotation.
B.
Modify the cluster with an HSM encryption option and automatic key rotation.
Answers
B.
Modify the cluster with an HSM encryption option and automatic key rotation.
C.
Create a new HSM-encrypted Amazon Redshift cluster and migrate the data to the new cluster.
Answers
C.
Create a new HSM-encrypted Amazon Redshift cluster and migrate the data to the new cluster.
D.
Enable HSM with key rotation through the AWS CLI.
Answers
D.
Enable HSM with key rotation through the AWS CLI.
E.
Enable Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) encryption in the HSM.
Answers
E.
Enable Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) encryption in the HSM.
Suggested answer: B, D

Explanation:

Reference: https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html

asked 16/09/2024
Bruce Tablada
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first