exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 838 discussion

A company is running a highly sensitive application on Amazon EC2 backed by an Amazon RDS database. Compliance regulations mandate that all personally identifiable information (PII) be encrypted at rest.

Which solution should a solutions architect recommend to meet this requirement with the LEAST amount of changes to the infrastructure?

  • A. Deploy AWS Certificate Manager to generate certificates. Use the certificates to encrypt the database volume.
  • B. Deploy AWS CloudHSM, generate encryption keys, and use the keys to encrypt database volumes.
  • C. Configure SSL encryption using AWS Key Management Service (AWS KMS) keys to encrypt database volumes.
  • D. Configure Amazon Elastic Block Store (Amazon EBS) encryption and Amazon RDS encryption with AWS Key Management Service (AWS KMS) keys to encrypt instance and database volumes.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
boluwatito
Highly Voted 11 months, 3 weeks ago
Selected Answer: D
Amazon RDS relies on Amazon EBS volumes for storage. By configuring Amazon EBS encryption, the underlying storage volumes are encrypted.
upvoted 6 times
...
JA2018
Most Recent 4 months ago
Selected Answer: D
- Option D requires the least infrastructure modification as it leverages existing features of EBS and RDS to enable encryption with KMS keys. - This is the most straightforward way to meet the compliance requirement without significant changes to the existing setup.
upvoted 1 times
...
mk168898
5 months, 1 week ago
SSL/Certificate => encrypt in transit, so A and C are wrong. so i feel the answer is between B and D.
upvoted 2 times
...
sandordini
11 months ago
Selected Answer: D
Encryption should be KMS, SSL is for transit not at rest... Even though the question never mentioned any EBS volumes whatsoever, I would still go for D....
upvoted 4 times
...
zinabu
11 months, 3 weeks ago
answer:C
upvoted 2 times
...
zinabu
11 months, 3 weeks ago
answer:C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago