A SysOps Administrator has received a request from the Compliance Department to enforce encryption at rest of all new objects uploaded to the corp-compliance bucket. How can the Administrator enforce encryption on all objects uploaded to the bucket?
A.
Enable Amazon S3 default encryption on the bucket.
B.
Add the following policy statement to the bucket:
C.
Add the following policy statement to the IAM user permissions policy:
D.
Generate a presigned URL for the Amazon S3 PUT operation with server-side encryption flag set, and send the URL to the user.
The answer is A. The other options with IAM policies specify " aws secure transport false " which is used for encryption in transit while the question pertains to encryption at rest.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Realmee
9 months, 4 weeks agoMadaan
1 year, 10 months agoplaster
2 years, 1 month agoMadaan
1 year, 10 months ago