Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 801 discussion

A financial company needs to handle highly sensitive data. The company will store the data in an Amazon S3 bucket. The company needs to ensure that the data is encrypted in transit and at rest. The company must manage the encryption keys outside the AWS Cloud.

Which solution will meet these requirements?

  • A. Encrypt the data in the S3 bucket with server-side encryption (SSE) that uses an AWS Key Management Service (AWS KMS) customer managed key.
  • B. Encrypt the data in the S3 bucket with server-side encryption (SSE) that uses an AWS Key Management Service (AWS KMS) AWS managed key.
  • C. Encrypt the data in the S3 bucket with the default server-side encryption (SSE).
  • D. Encrypt the data at the company's data center before storing the data in the S3 bucket.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Johnoppong101
2 months ago
You get to do it, keep moving...
upvoted 3 times
...
Scheldon
4 months ago
Selected Answer: D
AnswerD Hence we need to encrypt data not only during the rest but during the transfer as well, we need execute client-side encyprion. SSE will only secure data during rest hence we can eliminate A,B and C. https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingClientSideEncryption.html
upvoted 1 times
...
chasingsummer
6 months, 3 weeks ago
Selected Answer: D
Given the requirement to manage encryption keys outside the AWS Cloud, option D is the most suitable solution, despite not directly utilizing AWS's native encryption services like SSE with AWS KMS. Instead, it leverages external encryption mechanisms controlled by the company.
upvoted 4 times
...
rondelldell
6 months, 3 weeks ago
A Key is safe but came from the customer
upvoted 2 times
...
Mikado211
7 months ago
Selected Answer: D
A, B and C need to have the key stored in AWS cloud. D is correct.
upvoted 3 times
...
osmk
7 months, 1 week ago
Selected Answer: D
Client-side encryption – You encrypt your data client-side and upload the encrypted data to Amazon S3. In this case, you manage the encryption process, encryption keys, and related tools.https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingClientSideEncryption.html
upvoted 3 times
...
giovanna_mag
7 months, 1 week ago
Selected Answer: D
For me it's D, it's the only one that provides encryption also in transit
upvoted 2 times
...
asdfcdsxdfc
7 months, 2 weeks ago
A looks correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...