Hard1 markMultiple Choice
Domain 1.2: Security ControlsKMSEncryptionSecurity

AWS SAP-C02 · Question 13 · Domain 1.2: Security Controls

A company requires strict data residency and encryption controls. They must use AWS KMS for encryption, but the key material must be generated and stored in an on-premises Hardware Security Module (HSM). Which TWO steps are required to implement this? (Select TWO)

Answer options:

A.

Create a KMS key with no key material (external key store).

B.

Use AWS CloudHSM to generate the key material and link it to KMS.

C.

Establish a VPC Peering connection to the on-premises data center.

D.

Download the public key and import token from KMS, encrypt the key material on-premises, and upload it to KMS.

E.

Configure KMS to use AWS Direct Connect to fetch the key dynamically for every encryption request.

F.

Enable S3 Server-Side Encryption with Customer-Provided Keys (SSE-C).

How to approach this question

Identify the Bring Your Own Key (BYOK) process for AWS KMS.

Full Answer

A,D
To use on-premises generated key material in KMS (BYOK), you create a KMS key with no material, download the wrapping key and import token, encrypt your material on-premises, and import it.

Common mistakes

Confusing AWS CloudHSM with on-premises HSM requirements.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam