AWS SAP-C02 · Question 04 · Domain 1.2: Security Controls
A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted using customer-managed keys. The company has a strict requirement that the cryptographic material must be generated and stored in a single-tenant hardware appliance under their exclusive control. Which AWS service should the architect use?
Answer options:
AWS KMS with AWS managed keys
AWS KMS with imported key material
AWS CloudHSM
AWS Secrets Manager
75 questions · hints · full answers · grading