ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 304 - SCS-C01 discussion

Report
Export

You need to have a requirement to store objects in an S3 bucket with a key that is automatically managed and rotated. Which of the following can be used for this purpose? Please select:

A.
AWS KMS
Answers
A.
AWS KMS
B.
AWS S3 Server side encryption
Answers
B.
AWS S3 Server side encryption
C.
AWS Customer Keys
Answers
C.
AWS Customer Keys
D.
AWS Cloud HSM
Answers
D.
AWS Cloud HSM
Suggested answer: B

Explanation:

The AWS Documentation mentions the following

Server-side encryption protects data at rest. Server-side encryption with Amazon S3-managed encryption keys (SSE-S3) uses strong multi-factor encryption. Amazon S3 encrypts each object with a unique key. As an additional safeguard, it encrypts the key itself with a master key that it rotates regularly. Amazon S3 server-side encryption uses one of the strongest block ciphers available, 256-bit Advanced Encryption Standard (AES-256), to encrypt your data. All other options are invalid since here you need to ensure the keys are manually rotated since you manage the entire key set Using AWS S3 Server side encryption, AWS will manage the rotation of keys automatically. For more information on Server side encryption, please visit the following URL:

https://docs.aws.amazon.com/AmazonS3/latest/dev/UsineServerSideEncryption.htmllThe correct answer is: AWS S3 Server side encryption Submit your Feedback/Queries to our Experts

asked 16/09/2024
Lance Herbst
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first