Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 678 discussion

A company stores sensitive data in Amazon S3. A solutions architect needs to create an encryption solution. The company needs to fully control the ability of users to create, rotate, and disable encryption keys with minimal effort for any data that must be encrypted.

Which solution will meet these requirements?

  • A. Use default server-side encryption with Amazon S3 managed encryption keys (SSE-S3) to store the sensitive data.
  • B. Create a customer managed key by using AWS Key Management Service (AWS KMS). Use the new key to encrypt the S3 objects by using server-side encryption with AWS KMS keys (SSE-KMS).
  • C. Create an AWS managed key by using AWS Key Management Service (AWS KMS). Use the new key to encrypt the S3 objects by using server-side encryption with AWS KMS keys (SSE-KMS).
  • D. Download S3 objects to an Amazon EC2 instance. Encrypt the objects by using customer managed keys. Upload the encrypted objects back into Amazon S3.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
meenkaza
Highly Voted 10 months, 3 weeks ago
Selected Answer: B
SSE-KMS with Customer Managed Key (Option B): This option allows you to create a customer managed key using AWS KMS. With a customer managed key, you have full control over key lifecycle management, including the ability to create, rotate, and disable keys with minimal effort. SSE-KMS also integrates with AWS Identity and Access Management (IAM) for fine-grained access control.
upvoted 9 times
...
MatAlves
Most Recent 2 months ago
Selected Answer: B
Having both awsgeek75 and pentium75 in the comment section makes me more confident about my own answers.
upvoted 3 times
...
rubiteb
8 months, 3 weeks ago
Selected Answer: C
Customer needs to control the 'user's ability' and not the management of the keys. Option C will prevent users to have this ability.
upvoted 1 times
...
awsgeek75
10 months, 1 week ago
Selected Answer: B
Has to be customer manages to AC are not useful D is just wrong way of doing this B give full control to customer while using S3 server side encryption.
upvoted 2 times
...
pentium75
10 months, 3 weeks ago
Selected Answer: B
A and C do not allow the company "to fully control the ability of users to create, rotate, and disable encryption keys". D is anything but "minimal effort".
upvoted 3 times
...
Riajul
10 months, 3 weeks ago
Selected Answer: B
Option B should be correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...