exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 768 discussion

Exam question from Amazon's AWS-SysOps
Question #: 768
Topic #: 1
[All AWS-SysOps Questions]

A Development team is designing an application that processes sensitive information within a hybrid deployment. The team needs to ensure the application data is protected both in transit and at rest.
Which combination of actions should be taken to accomplish this? (Choose two.)

  • A. Use a VPN to set up a tunnel between the on-premises data center and the AWS resources
  • B. Use AWS Certificate Manager to create TLS/SSL certificates
  • C. Use AWS CloudHSM to encrypt the data
  • D. Use AWS KMS to create TLS/SSL certificates
  • E. Use AWS KMS to manage the encryption keys used for data encryption
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️
Reference:
https://wa.aws.amazon.com/wat.question.SEC_10.en.html
https://aws.amazon.com/blogs/database/best-practices-for-securing-sensitive-data-in-aws-data-stores/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kiev
Highly Voted 2 years, 6 months ago
A and E are the correct answers.
upvoted 14 times
...
AWS_Noob
Highly Voted 2 years, 7 months ago
B & E B - Create the Cert using ACM which will encrypt data in transit E keep data at rest encrypted using keys I had thought A, but stating "VPN" and not direct connect is what throws it off
upvoted 12 times
kung07
2 years, 7 months ago
A as such is not wrong, but you still need certificates, and as you can only choose 2 options, B&E is the better combination. Refer to https://docs.aws.amazon.com/vpc/latest/userguide/vpn-connections.html
upvoted 2 times
Phil31
2 years, 7 months ago
For me the answers are A & E You can't select Direct Connect because it's not in the answers choice, but a site tou site VPN a secure way to protect data in transit. With the B, what are you doing once you get your certificates ?
upvoted 5 times
...
jaribu
2 years, 7 months ago
You can use pre-shared keys, or certificates to authenticate your Site-to-Site VPN tunnel endpoints. At creation time, if you do not have certificates AWS provides by default a pre-shared key.
upvoted 2 times
...
...
...
albert_kuo
Most Recent 9 months, 3 weeks ago
Selected Answer: AE
A. Use a VPN to set up a tunnel between the on-premises data center and the AWS resources. Using a VPN (Virtual Private Network) establishes a secure connection between the on-premises data center and AWS resources, ensuring the encryption of data during transit. This helps protect the data while it is being transmitted between the on-premises environment and AWS. E. Use AWS KMS to manage the encryption keys used for data encryption. AWS Key Management Service (KMS) provides a secure and scalable solution for managing encryption keys. By using AWS KMS, the Development team can manage the encryption keys used to encrypt and decrypt sensitive data both in transit and at rest. This ensures that the data remains protected and only accessible to authorized entities.
upvoted 1 times
...
aidenpearce01
2 years, 1 month ago
Selected Answer: AE
creating an application that will handle sensitive data , but does the data go thru ELB ? if yes then ACM it's correct but if not the application just need to upload file to s3 thru VPN Gateway then i think not. So confuse I go with A & E
upvoted 1 times
...
Pradhan
2 years, 6 months ago
I will go with A & E
upvoted 2 times
...
TroyMcLure
2 years, 6 months ago
Correct Answer: A & E
upvoted 1 times
...
RicardoD
2 years, 6 months ago
B | E are the answers
upvoted 1 times
...
hdbs
2 years, 6 months ago
B is incorrect. The answer does not mention how these certificates will be used. They could be useful for end-to-end encryption but this is dependent on application design so it’s unclear if this is a suitable option. answer: A, E
upvoted 2 times
...
hdbs
2 years, 6 months ago
A, E ..
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
B. Use AWS Certificate Manager to create TLS/SSL certificates E. Use AWS KMS to manage the encryption keys used for data encryption
upvoted 1 times
...
jackdryan
2 years, 6 months ago
I'll go with B,E
upvoted 2 times
...
Mario799
2 years, 6 months ago
Believe B & E VPN for only one application? Generally the hybrid cloud is created with Direct Connect. VPN is used as failover. Development team will have more flexibility with the use of ACM and SSL certificates.
upvoted 1 times
...
MFDOOM
2 years, 6 months ago
B. Use AWS Certificate Manager to create TLS/SSL certificates E. Use AWS KMS to manage the encryption keys used for data encryption
upvoted 4 times
...
Thabo_Ramoshai
2 years, 6 months ago
ANS A & E hybrid deployment, therefore connection is between cloud and on-prem. Furthermore, connection should be encrypted Encrypt with VPN for data in transit & Encrypt with KMS for data at rest
upvoted 6 times
...
vnsuk
2 years, 6 months ago
we dont know if the vpn is backed by xconnect or site to site vpn. if it were site to site vpn then it support ip sec which protects data by encrypting data in transit. B and E is correct.
upvoted 1 times
...
waterzhong
2 years, 6 months ago
At first I thought A but IPSEC does not supply end to end encryption, but only encrypts traffic while going over the tunnel. End to End encryption would be a little safer in my opinion. Therefore I will go with B and E. Encryption in transit and encryption at rest.
upvoted 2 times
...
Pirulou
2 years, 6 months ago
In transit (VPN) and a rest (AWS KMS) A&E
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago