exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 638 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 638
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

Which encryption types can be used to protect objects at rest in Amazon S3? (Choose two.)

  • A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3)
  • B. Server-side encryption with AWS KMS managed keys (SSE-KMS)
  • C. TLS
  • D. SSL
  • E. Transparent Data Encryption (TDE)
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
chalaka
1 year ago
Selected Answer: AB
The encryption types that can be used to protect objects at rest in Amazon S3 are: A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) B. Server-side encryption with AWS KMS managed keys (SSE-KMS) These options provide encryption for data stored in Amazon S3. SSE-S3 and SSE-KMS encrypt data at the object level using encryption keys managed by Amazon S3 and AWS Key Management Service (KMS), respectively.
upvoted 1 times
...
Pranava_GCP
1 year, 8 months ago
Selected Answer: AB
A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) B. Server-side encryption with AWS KMS managed keys (SSE-KMS)
upvoted 3 times
...
roberjunquera
1 year, 11 months ago
Selected Answer: AB
The correct answers are: A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) B. Server-side encryption with AWS KMS managed keys (SSE-KMS) Explanation: Amazon S3 provides various encryption types to protect objects at rest, including server-side encryption with Amazon S3 managed encryption keys (SSE-S3), server-side encryption with AWS KMS managed keys (SSE-KMS), and server-side encryption with customer-provided encryption keys (SSE-C). TLS and SSL are encryption protocols used for securing data in transit, and Transparent Data Encryption (TDE) is a feature provided by database services like Amazon RDS and Amazon Aurora for encrypting data at rest.
upvoted 4 times
...
RajithaR
2 years, 1 month ago
Selected Answer: AB
A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) and B. Server-side encryption with AWS KMS managed keys (SSE-KMS) are two encryption types that can be used to protect objects at rest in Amazon S3.
upvoted 1 times
...
wabosi
2 years, 2 months ago
Selected Answer: AB
I vote AB
upvoted 3 times
...
fryderyk
2 years, 2 months ago
Selected Answer: AB
Definitely not TLS and SSL. They pertain to data in transit, not at rest.
upvoted 3 times
...
ptoul74
2 years, 2 months ago
AB, I agree
upvoted 1 times
...
wooyourdaddy
2 years, 2 months ago
Selected Answer: AB
A. Server-side encryption with Amazon S3 managed encryption keys (SSE-S3) B. Server-side encryption with AWS KMS managed keys (SSE-KMS) Data protection refers to protecting data while in-transit (as it travels to and from Amazon S3) and at rest (while it is stored on disks in Amazon S3 data centers). You can protect data in transit using Secure Socket Layer/Transport Layer Security (SSL/TLS) or client-side encryption. You have the following options for protecting data at rest in Amazon S3: Server-Side Encryption – Request Amazon S3 to encrypt your object before saving it on disks in its data centers and then decrypt it when you download the objects. To configure server-side encryption, see Specifying server-side encryption with AWS KMS (SSE-KMS) or Specifying Amazon S3 encryption. Ref link: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingEncryption.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago