ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 329 - SCS-C01 discussion

Report
Export

A company is using a Redshift cluster to store their data warehouse. There is a requirement from the Internal IT Security team to ensure that data gets encrypted for the Redshift database. How can this be achieved? Please select:

A.
Encrypt the EBS volumes of the underlying EC2 Instances
Answers
A.
Encrypt the EBS volumes of the underlying EC2 Instances
B.
Use AWS KMS Customer Default master key
Answers
B.
Use AWS KMS Customer Default master key
C.
Use SSL/TLS for encrypting the data
Answers
C.
Use SSL/TLS for encrypting the data
D.
Use S3 Encryption
Answers
D.
Use S3 Encryption
Suggested answer: B

Explanation:

The AWS Documentation mentions the following

Amazon Redshift uses a hierarchy of encryption keys to encrypt the database. You can use either AWS Key Management Servic (AWS KMS) or a hardware security module (HSM) to manage the toplevel encryption keys in this hierarchy. The process that Amazon Redshift uses for encryption differs depending on how you manage keys.

Option A is invalid because its the cluster that needs to be encrypted

Option C is invalid because this encrypts objects in transit and not objects at rest

Option D is invalid because this is used only for objects in S3 buckets For more information on Redshift encryption, please visit the following URL:

https://docs.aws.amazon.com/redshift/latest/memt/workine-with-db-encryption.htmllThe correct answer is: Use AWS KMS Customer Default master key Submit your Feedback/Queries toour Experts

asked 16/09/2024
Amir Trujillo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first