List of questions
Related questions
Question 297 - SCS-C01 discussion
A company continually generates sensitive records that it stores in an S3 bucket. All objects in the bucket are encrypted using SSE-KMS using one of the company's CMKs. Company compliance policies require that no more than one month of data be encrypted using the same encryption key.
What solution below will meet the company's requirements?
Please select:
A.
Trigger a Lambda function with a monthly CloudWatch event that creates a new CMK and updates the S3 bucket to use the new CMK.
B.
Configure the CMK to rotate the key material every month.
C.
Trigger a Lambda function with a monthly CloudWatch event that creates a new CMK, updates the S3 bucket to use thfl new CMK, and deletes the old CMK.
D.
Trigger a Lambda function with a monthly CloudWatch event that rotates the key material in the CMK.
Your answer:
0 comments
Sorted by
Leave a comment first