List of questions
Related questions
Question 824 - SAA-C03 discussion
A company is designing an application on AWS that processes sensitive data. The application stores and processes financial data for multiple customers.
To meet compliance requirements, the data for each customer must be encrypted separately at rest by using a secure, centralized key management solution. The company wants to use AWS Key Management Service (AWS KMS) to implement encryption.
Which solution will meet these requirements with the LEAST operational overhead'?
A.
Generate a unique encryption key for each customer. Store the keys in an Amazon S3 bucket. Enable server-side encryption.
B.
Deploy a hardware security appliance in the AWS environment that securely stores customer-provided encryption keys. Integrate the security appliance with AWS KMS to encrypt the sensitive data in the application.
C.
Create a single AWS KMS key to encrypt all sensitive data across the application.
D.
Create separate AWS KMS keys for each customer's data that have granular access control and logging enabled.
Your answer:
0 comments
Sorted by
Leave a comment first