ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 191 - SCS-C01 discussion

Report
Export

Due to new compliance requirements, a Security Engineer must enable encryption with customerprovided keys on corporate data that is stored in DynamoDB. The company wants to retain full control of the encryption keys. Which DynamoDB feature should the Engineer use to achieve compliance'?

A.
Use AWS Certificate Manager to request a certificate. Use that certificate to encrypt data prior to uploading it to DynamoDB.
Answers
A.
Use AWS Certificate Manager to request a certificate. Use that certificate to encrypt data prior to uploading it to DynamoDB.
B.
Enable S3 server-side encryption with the customer-provided keys. Upload the data to Amazon S3, and then use S3Copy to move all data to DynamoDB
Answers
B.
Enable S3 server-side encryption with the customer-provided keys. Upload the data to Amazon S3, and then use S3Copy to move all data to DynamoDB
C.
Create a KMS master key. Generate per-record data keys and use them to encrypt data prior to uploading it to DynamoDS. Dispose of the cleartext and encrypted data keys after encryption without storing.
Answers
C.
Create a KMS master key. Generate per-record data keys and use them to encrypt data prior to uploading it to DynamoDS. Dispose of the cleartext and encrypted data keys after encryption without storing.
D.
Use the DynamoDB Java encryption client to encrypt data prior to uploading it to DynamoDB.
Answers
D.
Use the DynamoDB Java encryption client to encrypt data prior to uploading it to DynamoDB.
Suggested answer: D

Explanation:

Follow the link: https://docs.aws.amazon.com/dynamodb-encryption-client/latest/devguide/whatis-ddb-encrypt.html

asked 16/09/2024
Fadi Iraqi
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first