exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 482 discussion

A company needs to use an AWS Transfer Family SFTP-enabled server with an Amazon S3 bucket to receive updates from a third-party data supplier. The data is encrypted with Pretty Good Privacy (PGP) encryption. The company needs a solution that will automatically decrypt the data after the company receives the data.
A solutions architect will use a Transfer Family managed workflow. The company has created an IAM service role by using an IAM policy that allows access to AWS Secrets Manager and the S3 bucket. The role’s trust relationship allows the transfer amazonaws.com service to assume the role.

What should the solutions architect do next to complete the solution for automatic decryption?

  • A. Store the PGP public key in Secrets Manager. Add a nominal step in the Transfer Family managed workflow to decrypt files. Configure PGP encryption parameters in the nominal step. Associate the workflow with the Transfer Family server.
  • B. Store the PGP private key in Secrets Manager. Add an exception-handling step in the Transfer Family managed workflow to decrypt files. Configure PGP encryption parameters in the exception handler. Associate the workflow with the SFTP user.
  • C. Store the PGP private key in Secrets Manager. Add a nominal step in the Transfer Family managed workflow to decrypt files. Configure PGP decryption parameters in the nominal step. Associate the workflow with the Transfer Family server.
  • D. Store the PGP public key in Secrets Manager. Add an exception-handling step in the Transfer Family managed workflow to decrypt files. Configure PGP decryption parameters in the exception handler. Associate the workflow with the SFTP user.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zapper1234
Highly Voted 10 months ago
The answer should be "C" because you store the "private" key in Secrets Manager
upvoted 7 times
...
AzureDP900
Most Recent 5 months, 2 weeks ago
C and D are pretty similar however D talks about exception handling. C is right answer
upvoted 1 times
AzureDP900
5 months, 2 weeks ago
store the PGP private key in Secrets Manager. Add a nominal step in the Transfer Family managed workflow to decrypt files.
upvoted 1 times
...
...
mark_232323
9 months, 2 weeks ago
Selected Answer: C
C correct
upvoted 1 times
...
dzhang344
9 months, 2 weeks ago
Selected Answer: C
C, for sure.
upvoted 1 times
...
gfhbox0083
9 months, 3 weeks ago
C, for sure. In the context of AWS Transfer Family managed workflows, a ""nominal step"" refers to one of the predefined steps that you can include in a managed workflow to automate file transfer and processing tasks. An ""exception-handling step"" is a specific type of step designed to handle errors or exceptions that occur during the execution of a workflow.
upvoted 3 times
...
grandcanyon
9 months, 4 weeks ago
Selected Answer: C
C is correct b/c private key is what is required for decryption
upvoted 2 times
...
Helpnosense
10 months ago
Selected Answer: C
Agree with Zapper1234 plus the permission is granted to transfer family server.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago