For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 4Question 12
    Hard1 markMultiple Choice
    Domain 1.2: Security ControlsMigrationSnowballKMSCloudHSM

    AWS SAP-C02 · Question 12 · Domain 1.2: Security Controls

    An enterprise is migrating its on-premises data lake to Amazon S3. They have 5 PB of data. The data must be encrypted at rest using keys managed by the enterprise's on-premises Hardware Security Module (HSM). The migration must be completed within 30 days, and their internet connection is 1 Gbps, heavily utilized by other workloads. Which combination of steps should the architect take? (Select THREE)

    Answer options:

    A.

    Use AWS DataSync over the existing internet connection.

    B.

    Order multiple AWS Snowball Edge Storage Optimized devices.

    C.

    Use AWS KMS with imported key material from the on-premises HSM.

    D.

    Configure AWS KMS to use a Custom Key Store backed by AWS CloudHSM.

    E.

    Establish a Site-to-Site VPN to synchronize the on-premises HSM with AWS CloudHSM.

    F.

    Use AWS Storage Gateway Volume Gateway.

    G.

    Order an AWS Snowmobile.

    How to approach this question

    Calculate transfer time (5PB over 1Gbps = too slow -> Snowball). Identify KMS Custom Key Store for HSM integration.

    Full Answer

    Use AWS Snowball Edge Storage Optimized devices. Use AWS KMS with a custom key store (AWS CloudHSM). Configure CloudHSM to synchronize with the on-premises HSM.
    Transferring 5 PB over a 1 Gbps link would take over a year, so AWS Snowball Edge is required. To use keys managed by an HSM, AWS KMS Custom Key Store backed by AWS CloudHSM is used, which can be synchronized with the on-premises HSM over a VPN/DX.

    Common mistakes

    Selecting DataSync without doing the math on transfer time.
    Question 11All questionsQuestion 13

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 4

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is redesigning its network architecture across 50 AWS accounts. They require ...HardQ02A financial services company uses AWS Organizations to manage 100+ accounts. The security team ma...MediumQ03An e-commerce company requires a multi-region active-active architecture for its critical order p...MediumQ04A company is setting up a new AWS environment using AWS Control Tower. They need to ensure that a...HardQ05An enterprise has 50 AWS accounts under AWS Organizations. They want to implement a chargeback mo...Medium
    View all 75 questions →