exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 942 discussion

A company regularly uploads confidential data to Amazon S3 buckets for analysis.

The company's security policies mandate that the objects must be encrypted at rest. The company must automatically rotate the encryption key every year. The company must be able to track key rotation by using AWS CloudTrail. The company also must minimize costs for the encryption key.

Which solution will meet these requirements?

  • A. Use server-side encryption with customer-provided keys (SSE-C)
  • B. Use server-side encryption with Amazon S3 managed keys (SSE-S3)
  • C. Use server-side encryption with AWS KMS keys (SSE-KMS)
  • D. Use server-side encryption with customer managed AWS KMS keys
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nebajp
Highly Voted 5 months ago
Selected Answer: C
SSE keys provided usage fee application and there is no monthly charges, hence its a correct option. D is highly cost option with monthly and usage fee. which is incorrect.
upvoted 8 times
...
joanna91
Most Recent 1 day, 8 hours ago
Selected Answer: C
"Automatically" rotate, then make it handled by AWS service, not by customer -> C, not D
upvoted 2 times
...
LeonSauveterre
1 week, 2 days ago
Selected Answer: D
"automatically rotate the encryption key" => C or D (because of KMS), then "able to track key rotation" => Just D.
upvoted 1 times
...
Anyio
2 weeks, 5 days ago
Selected Answer: D
Option C: Incorrect. Though server-side encryption with AWS KMS keys (SSE-KMS) would allow AWS to manage keys and enable logging via AWS CloudTrail, this option uses AWS-managed keys instead of customer-managed keys, limiting control over key rotations. Additionally, there can be more costs involved in using AWS-managed KMS keys compared to the customer managing their own. Option D: Correct. Using server-side encryption with customer-managed AWS KMS keys allows the company to have full control over the encryption keys, including managing and ensuring automatic rotation every year. Moreover, AWS CloudTrail can be employed to log events associated with AWS KMS, enabling the tracking of when keys are rotated. This option balances cost-effectiveness with the operational requirements specified, as it provides the necessary control without unnecessary expenses from more specialized AWS services.
upvoted 1 times
...
JA2018
1 month, 1 week ago
Selected Answer: D
I will choose Option D for the following reasons: #1 Automatic key rotation: AWS KMS allows you to set up automatic key rotation for customer managed keys, which fulfills the requirement to rotate encryption keys yearly. # 2 CloudTrail tracking: All KMS key operations are logged in CloudTrail, enabling you to track key rotation activity. #3 Lowest cost: While using customer-provided keys (SSE-C) might seem cost-effective at first glance, managing your own keys adds complexity and can be more expensive in the long run. #$ Compliance with security policies: Using customer managed KMS keys ensures that the company has full control over the encryption keys, meeting the stringent security requirements
upvoted 1 times
...
XXXXXlNN
2 months, 3 weeks ago
D auto-rotation feature > customer managed key
upvoted 1 times
...
XXXXXlNN
3 months, 2 weeks ago
D. customer needs to see the logs from Cloudtrail!
upvoted 1 times
sOI852POL
2 months, 3 weeks ago
Even with AWS KMS keys, rotation is logged on ctrail. Answer is D. https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html#:~:text=Monitoring%20key%20rotation,key%20was%20rotated.
upvoted 1 times
...
...
sOI852POL
4 months ago
Selected Answer: C
Answer is C. There is no monthly fee for AWS managed keys https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html#aws-managed-cmk
upvoted 3 times
...
elmyth
4 months, 2 weeks ago
Selected Answer: C
Customer managed key: Monthly fee (pro-rated hourly) + Per-use fee + rotation and cloudtrail AWS managed key: No monthly fee + Per-use fee (some AWS services pay this fee for you)+ rotation and cloudtrail
upvoted 4 times
...
dhewa
4 months, 3 weeks ago
Selected Answer: D
D gives you control, allows you to customise for example rotation policies to suit your compliance needs.
upvoted 2 times
...
komorebi
5 months ago
Selected Answer: D
Answer is D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago