Easy1 markMultiple Choice
Domain 1.3: Data SecuritySecurityS3KMSEncryption

AWS SAA-C03 · Question 06 · Domain 1.3: Data Security

A company requires that all data stored in Amazon S3 must be encrypted at rest using keys managed by the company. The company wants to maintain full control over the key rotation and auditing of key usage. <br/><br/>Which encryption option meets these requirements?

Answer options:

A.

Server-Side Encryption with Amazon S3 Managed Keys (SSE-S3)

B.

Server-Side Encryption with AWS KMS AWS Managed Keys (SSE-KMS)

C.

Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS)

D.

Client-Side Encryption using the AWS Encryption SDK

How to approach this question

Identify the KMS key type that provides the customer with full control over rotation and policies.

Full Answer

C.Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS)✓ Correct
Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS)
AWS KMS Customer Managed Keys provide the highest level of control. You can establish and maintain their key policies, IAM policies, and grants, enable and disable them, rotate their cryptographic material, and audit their usage in AWS CloudTrail.

Common mistakes

Confusing AWS Managed Keys with Customer Managed Keys.

Practice the full AWS SAA-C03 Practice Exam 4

65 questions · hints · full answers · grading

More questions from this exam