exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 112 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 112
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company maintains sensitive data in an Amazon S3 bucket that must be protected using an AWS KMS CMK. The company requires that keys be rotated automatically every year.
How should the bucket be configured?

  • A. Select server-side encryption with Amazon S3-managed keys (SSE-S3) and select an AWS-managed CMK.
  • B. Select Amazon S3-AWS KMS managed encryption keys (S3-KMS) and select a customer-managed CMK with key rotation enabled.
  • C. Select server-side encryption with Amazon S3-managed keys (SSE-S3) and select a customer-managed CMK that has imported key material.
  • D. Select server-side encryption with AWS KMS-managed keys (SSE-KMS) and select an alias to an AWS-managed CMK.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
luis12345
Highly Voted 3 years, 7 months ago
100% B
upvoted 27 times
awssecuritynewbie
3 years, 7 months ago
are you sure because D makes more sense... also there is not a option called " (S3-KMS" .... can you explain a bit why you think it is B
upvoted 1 times
Opiyo
3 years, 7 months ago
but then AWS-managed CMK is rotated once every three years
upvoted 1 times
GSH
3 years, 6 months ago
not with a customer provided key into KMS. This question was earlier in the list of questions, and everyone agreed with B then. It is B now...
upvoted 2 times
...
...
awssecuritynewbie
3 years, 6 months ago
I was a fool before now i am more wise! B is correct as you need to enable automatic rotation.
upvoted 5 times
...
...
...
Balki
Highly Voted 2 years, 4 months ago
Selected Answer: D
AWS Managed keys can be rotated every year now
upvoted 11 times
...
Arad
Most Recent 11 months, 2 weeks ago
Selected Answer: B
B is the right answer not D. Question is asking for key rotation.
upvoted 1 times
...
Anto1973
1 year, 8 months ago
Selected Answer: D
For those saying B, go into the console and find S3-KMS...answer's D every day of the week
upvoted 1 times
...
scanner2
1 year, 10 months ago
Selected Answer: D
Answer is D.
upvoted 1 times
...
matrpro
1 year, 12 months ago
Selected Answer: D
A, C- SSE-S3 encrypts the data key with a master key that is regularly rotated. however, you cannot define the rotation as annually. B is wrong because S3-KMS does not exist. D is the correct. Now, it can be changed every year, it was 3 years some time ago D - AWS Managed CMK is 3 years rotation.
upvoted 1 times
...
Dmosh
2 years ago
Selected Answer: D
You can use SSE-KMS with either customer managed key or the default AWS managed key. You can set yours to rotate every one year + AWS key now rotates every annualy instead of each 3 years.
upvoted 1 times
...
ITGURU51
2 years ago
B is wrong because there is no S3-KMS. It should be SS3-KMS. Therefore D is the best option.
upvoted 1 times
...
Nikhil0222
2 years ago
B -To protect the sensitive data in an Amazon S3 bucket, the bucket should be configured with server-side encryption. The AWS Key Management Service (KMS) can be used to manage the encryption keys. To automatically rotate the keys every year, a customer-managed CMK with key rotation enabled should be used.
upvoted 2 times
...
ITGURU51
2 years ago
AWS automatically rotates key material for AWS-owned and AWS-managed keys. Rotation is done annually for AWS-managed keys, whilst customers can choose to enable annual rotation for some Customer-managed keys. D
upvoted 1 times
...
architectwithus
2 years, 4 months ago
Selected Answer: D
A and C are wrong. There is nothing called S3-KMS, so B is out, the correct answer is D because as of May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years to every year. https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html#rotate-aws-managed-keys
upvoted 4 times
...
GeorgeDobrisan
2 years, 5 months ago
Automatic key rotation is not supported on the following types of KMS keys: KMS keys with imported key material - so C is out.
upvoted 2 times
...
[Removed]
2 years, 6 months ago
Selected Answer: D
D. S3-KMS does not exist, it is called SSE-KMS. AWS managed keys are rotated every year now
upvoted 2 times
...
iamsrk
2 years, 6 months ago
D is correct as AWS managed keys can now be rotated automatically every 1 year ,this change was done in May 2022,refer:https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html#rotate-aws-managed-keys
upvoted 3 times
...
sapien45
2 years, 8 months ago
Selected Answer: B
Select Amazon S3-AWS KMS managed encryption keys (S3-KMS) and select a customer-managed CMK with key rotation enabled.
upvoted 1 times
...
vbal
2 years, 8 months ago
D because starting May 2022 AWS Managed Keys are rotated every Year Automateically.
upvoted 1 times
...
MDJago
2 years, 8 months ago
AWS Managed keys are now rotated every year, as at may 2022 https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html#rotate-aws-managed-keys
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago