exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 178 discussion

A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers.

The application will send the credit card numbers to a component that is running in an isolated environment. The component will encrypt, store, and decrypt the numbers. The component then will issue tokens to replace the numbers in other parts of the application.

The component of the application that manages the tokenization process will be deployed on a separate set of EC2 instances. Other components of the application must not be able to store or access the credit card numbers.

Which solution will meet these requirements?

  • A. Use EC2 Dedicated Instances for the tokenization component of the application.
  • B. Place the EC2 instances that manage the tokenization process into a partition placement group.
  • C. Create a separate VPDeploy new EC2 instances into the separate VPC to support the data tokenization.
  • D. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IPLogic
4 months, 3 weeks ago
Selected Answer: D
The best solution to meet these requirements is: D. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances. AWS Nitro Enclaves provide an isolated environment that is ideal for processing sensitive data, such as credit card numbers. They offer strong security guarantees by isolating the tokenization process from other components of the application, ensuring that sensitive data is protected and inaccessible to unauthorized components
upvoted 1 times
...
VPNalumni
6 months, 2 weeks ago
D. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances. Explanation: AWS Nitro Enclaves provide isolated compute environments to process highly sensitive data, ensuring that other components cannot access the credit card numbers. Nitro Enclaves are specifically designed for secure processing of confidential information, making them ideal for tokenization tasks. https://aws.amazon.com/ec2/nitro/nitro-enclaves/
upvoted 1 times
...
mikelord
6 months, 4 weeks ago
Option D, deploying the tokenization component onto AWS Nitro Enclaves, is the best solution. Nitro Enclaves provide a highly secure, isolated environment that can handle the encryption, storage, and tokenization of sensitive information without exposing it to other parts of the application, meeting the requirements for both isolation and data security.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago