exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 771 discussion

Exam question from Amazon's AWS-SysOps
Question #: 771
Topic #: 1
[All AWS-SysOps Questions]

A company issued SSL certificates to its users, and needs to ensure the private keys that are used to sign the certificates are encrypted. The company needs to be able to store the private keys and perform cryptographic signing operations in a secure environment.
Which service should be used to meet these requirements?

  • A. AWS CloudHSM
  • B. AWS KMS
  • C. AWS Certificate Manager
  • D. Amazon Connect
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.aws.amazon.com/acm/latest/userguide/kms.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AWS_Noob
Highly Voted 2 years, 7 months ago
A - the questions is asking to Store keys.
upvoted 12 times
neel376
2 years, 7 months ago
Should be C, ACM stores key for you in KMS. ACM covers it all https://docs.aws.amazon.com/acm/latest/userguide/data-protection.html
upvoted 3 times
jaribu
2 years, 6 months ago
ACM creates and manages its own keys, what about customer keys supplied by other Certificate Authorities? I think answer A is the most appropriate choice.
upvoted 4 times
...
...
kung07
2 years, 7 months ago
agree, additional info refer to https://docs.aws.amazon.com/cloudhsm/latest/userguide/key_mgmt_util-sign.html
upvoted 2 times
...
...
albert_kuo
Most Recent 9 months, 3 weeks ago
Selected Answer: A
AWS CloudHSM (Hardware Security Module) is a dedicated hardware appliance that provides secure key storage and cryptographic operations. It offers a secure and tamper-resistant environment for generating and storing private keys, and performs cryptographic operations such as signing and decryption. CloudHSM ensures the private keys remain within a secure hardware device, providing an additional layer of protection against unauthorized access.
upvoted 1 times
...
okm1997_2
1 year, 2 months ago
Answer => A => HSM. The Question here is that the company needs to handle cryptographic operations and store keys manually, whereas kms does it automatically by AWS
upvoted 1 times
...
gulu73
1 year, 2 months ago
Selected Answer: A
answer is A
upvoted 1 times
...
loki123
2 years, 2 months ago
A--- https://docs.aws.amazon.com/crypto/latest/userguide/awscryp-service-hsm.html Generate, store, import, export, and manage cryptographic keys, including symmetric keys and asymmetric key pairs.
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
A. AWS CloudHSM
upvoted 2 times
...
dozymars
2 years, 6 months ago
Answer is A
upvoted 1 times
...
moon_lee
2 years, 6 months ago
Google the line in question "store the private keys and perform cryptographic signing operations in a secure environment" and the first thing you get is CloudHSM - https://docs.aws.amazon.com/crypto/latest/userguide/awscryp-service-hsm.html So my take is A considering all the facts
upvoted 1 times
...
tahaRyski
2 years, 6 months ago
A is correct. the company is concerned about Key storage and SSL Acceleration / precessing in a secure environment. all of these points to Cloud HSM https://docs.aws.amazon.com/cloudhsm/latest/userguide/introduction.html https://docs.aws.amazon.com/cloudhsm/latest/userguide/ssl-offload.html
upvoted 1 times
...
jackdryan
2 years, 6 months ago
I'll go with A
upvoted 1 times
...
MegatonN
2 years, 6 months ago
other doc: https://docs.aws.amazon.com/cloudhsm/latest/userguide/ssl-offload-import-or-generate-private-key-and-certificate.html Import an Existing Private Key You might already have a private key and a corresponding SSL/TLS certificate that you use for HTTPS on your web server. If so, you can import that key into an HSM by doing the following: To import an existing private key into an HSM 1. Connect to your Amazon EC2 client instance. If necessary, copy your existing private key and certificate to the instance. 2. Run the following command to start the AWS CloudHSM client.
upvoted 1 times
...
AWS1212
2 years, 6 months ago
"store the private keys" = A. AWS CloudHSM
upvoted 2 times
...
mrbreeze
2 years, 6 months ago
The correct answer is A https://docs.aws.amazon.com/cloudhsm/latest/userguide/use-cases.html#certificate-authority
upvoted 1 times
...
MrDEVOPS
2 years, 6 months ago
Ans A :- https://docs.aws.amazon.com/cloudhsm/latest/userguide/use-cases.html#certificate-authority
upvoted 1 times
...
JGD
2 years, 6 months ago
Answer A. ACM will be in use only when we are integrating SSL with ELb, S3, CloudFront. Still we can encrypt imported private key because AWS do not play with the security. Cloud HsM: this will be utilized in general like based on the question asked and it well suited.
upvoted 3 times
...
gretch
2 years, 7 months ago
A https://docs.aws.amazon.com/cloudhsm/latest/userguide/use-cases.html#certificate-authority
upvoted 1 times
...
neel376
2 years, 7 months ago
Answer selected is correct. Use ACM. ACM will store key in KMS for you https://docs.aws.amazon.com/acm/latest/userguide/data-protection.html
upvoted 3 times
jaribu
2 years, 7 months ago
What if I have my own SSL/TLS and do not require AWS to provide them?
upvoted 2 times
...
neel376
2 years, 7 months ago
So C is correct
upvoted 1 times
AWSum1
2 years, 7 months ago
Read the first paragraph here. https://docs.aws.amazon.com/cloudhsm/latest/userguide/use-cases.html#certificate-authority Based on this I'd say A is correct
upvoted 7 times
ImranR
2 years, 6 months ago
I was doubting for cryptographic signing operations by HSM but thanks for reference to clear...
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago