ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 769 - SAA-C03 discussion

Report
Export

A company is running a highly sensitive application on Amazon EC2 backed by an Amazon RDS database Compliance regulations mandate that all personally identifiable information (Pll) be encrypted at rest.

Which solution should a solutions architect recommend to meet this requirement with the LEAST amount of changes to the infrastructure?

A.
Deploy AWS Certificate Manager to generate certificates Use the certificates to encrypt the database volume
Answers
A.
Deploy AWS Certificate Manager to generate certificates Use the certificates to encrypt the database volume
B.
Deploy AWS CloudHSM. generate encryption keys, and use the keys to encrypt database volumes.
Answers
B.
Deploy AWS CloudHSM. generate encryption keys, and use the keys to encrypt database volumes.
C.
Configure SSL encryption using AWS Key Management Service {AWS KMS) keys to encrypt database volumes.
Answers
C.
Configure SSL encryption using AWS Key Management Service {AWS KMS) keys to encrypt database volumes.
D.
Configure Amazon Elastic Block Store (Amazon EBS) encryption and Amazon RDS encryption with AWS Key Management Service (AWS KMS) keys to encrypt instance and database volumes.
Answers
D.
Configure Amazon Elastic Block Store (Amazon EBS) encryption and Amazon RDS encryption with AWS Key Management Service (AWS KMS) keys to encrypt instance and database volumes.
Suggested answer: D

Explanation:

EBS Encryption:

Default EBS Encryption: Can be enabled for new EBS volumes.

Use of AWS KMS: Specify AWS KMS keys to handle encryption and decryption of data transparently.

Amazon RDS Encryption:

RDS Encryption: Encrypts the underlying storage for RDS instances using AWS KMS.

Configuration: Enable encryption when creating the RDS instance or modify an existing instance to enable encryption.

Least Amount of Changes:

Both EBS and RDS support seamless encryption with AWS KMS, requiring minimal changes to the existing infrastructure.

Enables compliance with regulatory requirements without modifying the application.

Operational Efficiency: Using AWS KMS for both EBS and RDS ensures a consistent, managed approach to encryption, simplifying key management and enhancing security.

Amazon EBS Encryption

Amazon RDS Encryption

AWS Key Management Service

asked 16/09/2024
Ali Diaz
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first