exam questions

Exam AWS Certified Developer - Associate DVA-C02 All Questions

View all questions & answers for the AWS Certified Developer - Associate DVA-C02 exam

Exam AWS Certified Developer - Associate DVA-C02 topic 1 question 150 discussion

A developer is planning to migrate on-premises company data to Amazon S3. The data must be encrypted, and the encryption keys must support automatic annual rotation. The company must use AWS Key Management Service (AWS KMS) to encrypt the data.

Which type of keys should the developer use to meet these requirements?

  • A. Amazon S3 managed keys
  • B. Symmetric customer managed keys with key material that is generated by AWS
  • C. Asymmetric customer managed keys with key material that is generated by AWS
  • D. Symmetric customer managed keys with imported key material
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PrakashM14
Highly Voted 1 year ago
Selected Answer: B
Asymmetric keys (option C) are typically used for different use cases, such as digital signatures and key pairs, and may not be as suitable for automatic rotation in the described scenario. Imported key material (option D) means that you bring your own key material, and AWS KMS doesn't support automatic rotation for such keys. Amazon S3 managed keys (option A) are used specifically for Amazon S3 and don't support automatic rotation. so, option B is correct
upvoted 13 times
...
65703c1
Most Recent 5 months ago
Selected Answer: B
B is the correct answer.
upvoted 1 times
...
SerialiDr
7 months, 3 weeks ago
Selected Answer: B
This option allows for automatic rotation of the keys, aligning with AWS best practices for key management and security. AWS KMS supports key rotation, which can be configured to occur automatically on an annual basis for customer managed keys. This ensures that data remains encrypted with a key that is periodically rotated, enhancing the security posture of the data stored in Amazon S3.
upvoted 2 times
...
KarBiswa
8 months ago
Selected Answer: B
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html Its a symmetric key rotation
upvoted 1 times
...
konieczny69
8 months, 3 weeks ago
Selected Answer: A
https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingServerSideEncryption.html Server-side encryption protects data at rest. Amazon S3 encrypts each object with a unique key. As an additional safeguard, it encrypts the key itself with a key that it rotates regularly. Amazon S3 server-side encryption uses 256-bit Advanced Encryption Standard Galois/Counter Mode (AES-GCM) to encrypt all uploaded objects.
upvoted 3 times
...
SerialiDr
9 months, 1 week ago
Selected Answer: B
B. Symmetric customer managed keys with key material that is generated by AWS: This option allows the developer to create and manage their own encryption keys in AWS KMS, with AWS generating the key material. AWS KMS supports automatic rotation of customer managed keys. You can configure the key to rotate automatically once per year.
upvoted 2 times
...
Certified101
10 months, 2 weeks ago
Selected Answer: B
B is correct, it must use KMS
upvoted 1 times
...
ShawnWon
11 months, 1 week ago
Option A (Amazon S3 managed keys) does not involve using AWS Key Management Service (AWS KMS) directly. Instead, it relies on Amazon S3 to manage the keys for server-side encryption. If the requirement is specifically to use AWS KMS for encryption, then Option A would not meet that requirement.
upvoted 1 times
...
wonder_man
12 months ago
Selected Answer: B
Only this option supports AWS KMS with the key rotation
upvoted 1 times
...
PrakashM14
1 year ago
Asymmetric keys (option C) are typically used for different use cases, such as digital signatures and key pairs, and may not be as suitable for automatic rotation in the described scenario. Imported key material (option D) means that you bring your own key material, and AWS KMS doesn't support automatic rotation for such keys. Amazon S3 managed keys (option A) are used specifically for Amazon S3 and don't support automatic rotation. so, option B is correct
upvoted 1 times
...
dilleman
1 year ago
Selected Answer: A
A: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingServerSideEncryption.html
upvoted 2 times
...
Digo30sp
1 year ago
Selected Answer: A
A) Amazon S3 Managed Keys https://docs.aws.amazon.com/pt_br/AmazonS3/latest/userguide/serv-side-encryption.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago