AWS SAA-C03 · Question 03 · Domain 1.3: Data Security
A company is storing highly sensitive data in an Amazon S3 bucket. The security team requires that the data is encrypted at rest using keys managed by the company, and that all API calls to the keys are logged. Which TWO actions should a solutions architect take? (Select TWO.)
Answer options:
Use Amazon S3 managed keys (SSE-S3).
Use AWS KMS Customer Managed Keys (CMKs).
Enable AWS CloudTrail to log KMS API calls.
Use AWS Secrets Manager to store the encryption keys.
Enable Amazon Macie to log key usage.
65 questions · hints · full answers · grading