exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 879 discussion

A company's compliance audit reveals that some Amazon Elastic Block Store (Amazon EBS) volumes that were created in an AWS account were not encrypted.
A solutions architect must implement a solution to encrypt all new EBS volumes at rest.
Which solution will meet this requirement with the LEAST effort?

  • A. Create an Amazon EventBridge (Amazon CloudWatch Events) rule to detect the creation of unencrypted EBS volumes. Invoke an AWS Lambda function to delete noncompliant volumes.
  • B. Use AWS Audit Manager with data encryption.
  • C. Create an AWS Config rule to detect the creation of a new EBS volume. Encrypt the volume by using AWS Systems Manager Automation.
  • D. Turn on EBS encryption by default in all AWS Regions.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
devilman222
3 months, 2 weeks ago
Selected Answer: D
The question asks how to encrypt "new" volumes. I guess we are not worrying about the older stuff for now.
upvoted 1 times
...
evargasbrz
1 year, 11 months ago
Selected Answer: D
D is correct.
upvoted 2 times
...
AwsBRFan
2 years, 1 month ago
Selected Answer: D
https://aws.amazon.com/premiumsupport/knowledge-center/ebs-automatic-encryption/
upvoted 3 times
...
dcdcdc3
2 years, 2 months ago
Selected Answer: D
Agree with D for all New volumes
upvoted 2 times
...
sb333
2 years, 2 months ago
Selected Answer: D
D is correct. The question is looking for the LEAST effort for encrypting "new" volumes. This is accomplished by turning on encryption by default, which will only allow encryption to be used unless it is turned off again. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#encryption-by-default If you want to correct current volumes, which the questions is not asking you to do, then you could follow-up with answer C as a solution (which requires a bit of configuration). Remember to only answer what the question is asking for and not try to solve things that it doesn't ask for.
upvoted 2 times
...
JohnPi
2 years, 2 months ago
Selected Answer: D
New Amazon EBS volumes aren't encrypted by default. However, there is a setting in the EC2 console that turns on encryption by default for all new Amazon EBS volumes and snapshot copies created within a specified Region.
upvoted 1 times
...
Malluchan
2 years, 2 months ago
D is correct , Since the ask is to encrypt all new EBS volumes. Existing unencrypted Volumes will be handled separately..
upvoted 1 times
...
Ni_yot
2 years, 2 months ago
Selected Answer: D
D as per link
upvoted 2 times
...
Ni_yot
2 years, 2 months ago
I will go with D as per the link already added
upvoted 1 times
...
cale
2 years, 3 months ago
Selected Answer: C
I think its C
upvoted 2 times
[Removed]
2 years, 1 month ago
Can encrypt un-encrypted EBS volumes.
upvoted 1 times
...
...
FF
2 years, 3 months ago
D is right. https://aws.amazon.com/premiumsupport/knowledge-center/ebs-automatic-encryption/
upvoted 4 times
...
gnic
2 years, 3 months ago
Selected Answer: C
It's C. Enabling encryption doesn't guarantee that ESB will be encrypted. You have to create a snapshot, create a new volume encrypted...
upvoted 2 times
Steven111
2 years ago
encrypt all new EBS volumes, NEW!
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...