ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 312 - SCS-C01 discussion

Report
Export

You have an EBS volume attached to an EC2 Instance which uses KMS for Encryption. Someone has now gone ahead and deleted the Customer Key which was used for the EBS encryption. What should be done to ensure the data can be decrypted.

Please select:

A.
Create a new Customer Key using KMS and attach it to the existing volume
Answers
A.
Create a new Customer Key using KMS and attach it to the existing volume
B.
You cannot decrypt the data that was encrypted under the CMK, and the data is not recoverable.
Answers
B.
You cannot decrypt the data that was encrypted under the CMK, and the data is not recoverable.
C.
Request AWS Support to recover the key
Answers
C.
Request AWS Support to recover the key
D.
Use AWS Config to recover the key
Answers
D.
Use AWS Config to recover the key
Suggested answer: B

Explanation:

Deleting a customer master key (CMK) in AWS Key Management Service (AWS KMS) is destructive and potentially dangerous. It deletes the key material and all metadata associated with the CMK, and is irreversible. After a CMK is deleted you can no longer decrypt the data that was encrypted under that CMK, which means that data becomes unrecoverable. You should delete a CMK only when you are sure that you don't need to use it anymore. If you are not sure, consider disabling the CMK instead of deleting it. You can re-enable a disabled CMK if you need to use it again later, but you cannot recover a deleted CMK. https://docs.aws.amazon.com/kms/latest/developerguide/deleting-keys.htmlA is incorrect because Creating a new CMK and attaching it to the exiting volume will not allow thedata to be decrypted, you cannot attach customer master keys after the volume is encryptedOption C and D are invalid because once the key has been deleted, you cannot recover it For moreinformation on EBS Encryption with KMS, please visit the following URL:

https://docs.aws.amazon.com/kms/latest/developerguide/services-ebs.htmlThe correct answer is: You cannot decrypt the data that was encrypted under the CMK, and the datais not recoverable. Submit your Feedback/Queries to our Experts

asked 16/09/2024
Darshak Ramdevputra
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first