AWS SAP-C02 · Question 08 · Domain 2.3: Security Controls
A financial application stores highly sensitive PII in Amazon S3. The security team requires that the data be encrypted at rest using keys managed by the company's on-premises Hardware Security Module (HSM). Which encryption strategy should be used?
Answer options:
Use Server-Side Encryption with Amazon S3 managed keys (SSE-S3).
Use Server-Side Encryption with AWS KMS keys (SSE-KMS) using AWS managed keys.
Use AWS KMS with imported key material generated by the on-premises HSM.
Use Client-Side Encryption, encrypting the data on-premises before uploading to S3.
75 questions · hints · full answers · grading