exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 605 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 605
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

Who enables encryption of data at rest for Amazon Elastic Block Store (Amazon EBS)?

  • A. AWS Support
  • B. AWS customers
  • C. AWS Key Management Service (AWS KMS)
  • D. AWS Trusted Advisor
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mohamed_Samir
Highly Voted 2 years, 2 months ago
Selected Answer: B
B. AWS Customers. -- Newly created Amazon EBS volumes aren't encrypted by default. -- You, as an AWS Customer, can turn on default encryption for new EBS volumes. >> https://aws.amazon.com/premiumsupport/knowledge-center/ebs-automatic-encryption/#:~:text=Short%20description,Cloud%20(Amazon%20EC2)%20console.
upvoted 8 times
...
thanglongsp
Most Recent 1 year, 3 months ago
C. AWS Key Management Service (AWS KMS) AWS KMS allows customers to create and manage encryption keys used to encrypt their data, including data stored in Amazon EBS volumes. Customers can choose to encrypt their EBS volumes using AWS-managed keys or their own customer-managed keys (CMKs) created and managed through AWS KMS. This provides a secure way to encrypt data stored in EBS volumes, ensuring its protection while at rest.
upvoted 1 times
...
Pranava_GCP
1 year, 8 months ago
Selected Answer: B
B. AWS customers
upvoted 2 times
...
linux_admin
2 years, 1 month ago
Selected Answer: B
Amazon EBS is a block-level storage service that provides persistent block storage volumes for use with Amazon EC2 instances. AWS customers can enable encryption of data at rest for Amazon EBS volumes by specifying an encryption key when creating a new volume, or by encrypting an existing volume using AWS KMS.
upvoted 1 times
...
fryderyk
2 years, 2 months ago
Selected Answer: B
'Who' implies a subject (AWS Customer)
upvoted 2 times
...
ptoul74
2 years, 2 months ago
I agree. The question is who, not what. Then, the correct answer is B.
upvoted 2 times
...
ptoul74
2 years, 2 months ago
The question is asking who is enabling the encryption. Therefore, it should be B, right?
upvoted 3 times
...
wooyourdaddy
2 years, 2 months ago
Selected Answer: C
C. AWS Key Management Service (AWS KMS) Amazon EBS encrypts your volume with a data key using industry-standard AES-256 data encryption. The data key is generated by AWS KMS and then encrypted by AWS KMS with your AWS KMS key prior to being stored with your volume information. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html
upvoted 2 times
jg_85
2 years, 2 months ago
It uses KMS for encryption however the user's responsibility to enable it. Therefore B - AWS Customers.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago