ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 797 - SAA-C03 discussion

Report
Export

A company uses Amazon EC2 instances and stores data on Amazon Elastic Block Store (Amazon EBS) volumes. The company must ensure that all data is encrypted at rest by using AWS Key Management Service (AWS KMS). The company must be able to control rotation of the encryption keys.

Which solution will meet these requirements with the LEAST operational overhead?

A.
Create a customer managed key Use the key to encrypt the EBS volumes.
Answers
A.
Create a customer managed key Use the key to encrypt the EBS volumes.
B.
Use an AWS managed key to encrypt the EBS volumes. Use the key to configure automatic key rotation.
Answers
B.
Use an AWS managed key to encrypt the EBS volumes. Use the key to configure automatic key rotation.
C.
Create an external KMS key with imported key material. Use the key to encrypt the EBS volumes.
Answers
C.
Create an external KMS key with imported key material. Use the key to encrypt the EBS volumes.
D.
Use an AWS owned key to encrypt the EBS volumes.
Answers
D.
Use an AWS owned key to encrypt the EBS volumes.
Suggested answer: A

Explanation:

To meet the requirement of controlling key rotation with minimal operational overhead, creating a customer managed key (CMK) in AWS KMS is the optimal solution. With CMKs, you can define custom key rotation policies, ensuring that you retain control over the key lifecycle, including enabling automatic key rotation every year.

Key AWS features:

Custom Key Management: A customer managed key allows you to control the key policies, lifecycle, and enable key rotation for compliance.

Least Operational Overhead: Using a customer managed key simplifies encryption management while offering more flexibility than AWS managed or owned keys.

AWS Documentation: The AWS Well-Architected Framework recommends customer managed keys for environments where key control and flexibility are required.

asked 16/09/2024
Wilson Sigcha
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first