ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 253 - SCS-C01 discussion

Report
Export

Your IT Security department has mandated that all data on EBS volumes created for underlying EC2 Instances need to be encrypted. Which of the following can help achieve this? Please select:

A.
AWS KMS API
Answers
A.
AWS KMS API
B.
AWS Certificate Manager
Answers
B.
AWS Certificate Manager
C.
API Gateway with STS
Answers
C.
API Gateway with STS
D.
IAM Access Key
Answers
D.
IAM Access Key
Suggested answer: A

Explanation:

The AWS Documentation mentions the following on AWS KMS

AWS Key Management Service (AWS KMS) is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. AWS KMS is integrated with other AWS services including Amazon Elastic Block Store (Amazon EBS), Amazon Simple Storage Service (Amazon S3), Amazon Redshift Amazon Elastic Transcoder, Amazon WorkMail, Amazon Relational Database Service (Amazon RDS), and others to make it simple to encrypt your data with encryption keys that you manage Option B is incorrect - The AWS Certificate manager can be used to generate SSL certificates that can be used to encrypt traffic transit, but not at rest Option C is incorrect is again used for issuing tokens when using API gateway for traffic in transit. Option D is used for secure access to EC2 Instances

For more information on AWS KMS, please visit the following URL:

https://docs.aws.amazon.com/kms/latest/developereuide/overview.htmllThe correct answer is: AWS KMS APISubmit your Feedback/Queries to our Experts

asked 16/09/2024
saud ahmed
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first