Hard1 markMultiple Choice

AWS SAP-C02 · Question 35 · Domain 2.3: Security Controls

An enterprise uses AWS KMS to manage encryption keys. They have a strict regulatory requirement that the cryptographic material must be generated and stored in a FIPS 140-2 Level 3 validated hardware appliance that they exclusively control. Which solution meets this requirement?

Answer options:

A.

Use standard AWS KMS Customer Managed Keys.

B.

Use AWS CloudHSM to generate the keys. Configure KMS to use a custom key store backed by the CloudHSM cluster.

C.

Import key material generated on-premises into AWS KMS.

D.

Use AWS Secrets Manager to store the keys.

How to approach this question

Look for the single-tenant HSM service in AWS.

Full Answer

B.Use AWS CloudHSM to generate the keys. Configure KMS to use a custom key store backed by the CloudHSM cluster.✓ Correct
Use AWS CloudHSM to generate the keys. Configure KMS to use a custom key store backed by the CloudHSM cluster.
AWS CloudHSM provides dedicated, FIPS 140-2 Level 3 validated HSMs. By using a KMS custom key store, you get the integration benefits of KMS while keeping the keys in your dedicated HSMs.

Common mistakes

Thinking standard KMS meets the 'exclusive control' requirement.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

75 questions · hints · full answers · grading

More questions from this exam