List of questions
Related questions
Question 213 - DOP-C01 discussion
A company is building a solution for storing files containing Personally Identifiable Information (PII) on AWS. Requirements state:
All data must be encrypted at rest and in transit.
All data must be replicated in at least two locations that are at least 500 miles apart.
Which solution meets these requirements?
A.
Create primary and secondary Amazon S3 buckets in two separate Availability Zones that are at least 500 miles apart. Use a bucket policy to enforce access to the buckets only through HTTPS. Use a bucket policy to enforce Amazon S3 SSECon all objects uploaded to the bucket. Configure cross-region replication between the two buckets.
B.
Create primary and secondary Amazon S3 buckets in two separate AWS Regions that are at least 500 miles apart. Use a bucket policy to enforce access to the buckets only through HTTPS. Use a bucket policy to enforce S3-Managed Keys (SSES3) on all objects uploaded to the bucket. Configure cross-region replication between the two buckets.
C.
Create primary and secondary Amazon S3 buckets in two separate AWS Regions that are at least 500 miles apart. Use an IAM role to enforce access to the buckets only through HTTPS. Use a bucket policy to enforce Amazon S3- Managed Keys (SSE-S3) on all objects uploaded to the bucket. Configure cross-region replication between the two buckets.
D.
Create primary and secondary Amazon S3 buckets in two separate Availability Zones that are at least 500 miles apart. Use a bucket policy to enforce access to the buckets only through HTTPS. Use a bucket policy to enforce AWS KMSencryption on all objects uploaded to the bucket. Configure cross-region replication between the two buckets. Create a KMSCustomer Master Key (CMK) in the primary region for encrypting objects.
Your answer:
0 comments
Sorted by
Leave a comment first