The SysOps Administrator must integrate an existing on-premises asymmetrical key management system into an AWS services platform. How can the Administrator meet this requirement?
A.
Implement AWS KMS and integrate with the existing on-premises asymmetrical key management system
B.
Implement AWS CloudHSM and integrate it with the existing key management infrastructure
C.
Deploy an Amazon EC2 instance and choose an AMI from an AWS partner in the AWS Marketplace
D.
Create a master key in AWS KMS, and export that key to the existing on-premises asymmetrical key management system
AWS CloudHSM provides dedicated Hardware Security Modules (HSMs) in the AWS cloud, allowing you to generate, store, and manage encryption keys securely. By integrating AWS CloudHSM with the existing key management infrastructure, the Administrator can maintain control over the keys and seamlessly extend the key management capabilities into the AWS environment.
From Nov 25, 2019, AWS Key Management Service (KMS) now enables you to create and use asymmetric customer master keys (CMKs) and data key pairs.
https://aws.amazon.com/about-aws/whats-new/2019/11/aws-key-management-service-supports-asymmetric-keys/
https://aws.amazon.com/cloudhsm/faqs/
Ans is B:
Q: Does CloudHSM work with on-premises HSMs?
Yes. While CloudHSM does not interoperate directly with on-premises HSMs, you can securely transfer exportable keys between CloudHSM and most commercial HSMs using one of several supported RSA key wrap methods.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
YashBindlish
Highly Voted 2 years, 7 months agoalbert_kuo
Most Recent 10 months agoRileyJr
2 years, 3 months agoa_w_s
2 years, 5 months agoa_w_s
2 years, 5 months agoAWS_Noob
2 years, 6 months agoANS0908431
2 years, 5 months agoANS0908431
2 years, 5 months agoJohncena
2 years, 6 months agoawsnoob
2 years, 6 months agokarmaah
2 years, 6 months agoPhilipAWS
2 years, 6 months agokarmaah
2 years, 6 months agosaumenP
2 years, 6 months ago