exam questions

Exam AWS Certified Data Analytics - Specialty All Questions

View all questions & answers for the AWS Certified Data Analytics - Specialty exam

Exam AWS Certified Data Analytics - Specialty topic 1 question 12 discussion

A banking company is currently using an Amazon Redshift cluster with dense storage (DS) nodes to store sensitive data. An audit found that the cluster is unencrypted. Compliance requirements state that a database with sensitive data must be encrypted through a hardware security module (HSM) with automated key rotation.
Which combination of steps is required to achieve compliance? (Choose two.)

  • A. Set up a trusted connection with HSM using a client and server certificate with automatic key rotation.
  • B. Modify the cluster with an HSM encryption option and automatic key rotation.
  • C. Create a new HSM-encrypted Amazon Redshift cluster and migrate the data to the new cluster.
  • D. Enable HSM with key rotation through the AWS CLI.
  • E. Enable Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) encryption in the HSM.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
testtaker3434
Highly Voted 3 years, 7 months ago
Answer should be A and C. Using HSM you have to create a new cluster (that eliminates B). See link below, it clearly states "You can't enable hardware security module (HSM) encryption by modifying the cluster. Instead, create a new, HSM-encrypted cluster and migrate your data to the new cluster" https://docs.aws.amazon.com/redshift/latest/mgmt/changing-cluster-encryption.html In the same link it says you have create certificates. My thinking that its not D, its because it can be already configured when you are settinp up the cluster. (option C)
upvoted 48 times
GeeBeeEl
3 years, 6 months ago
I dont agree with you on c...... that site you referenced says "When you modify your cluster to enable KMS encryption, Amazon Redshift automatically migrates your data to a new encrypted cluster. " also see https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html
upvoted 2 times
GeeBeeEl
3 years, 6 months ago
I see now why C is correct --- "To migrate an unencrypted cluster to a cluster encrypted using a hardware security module (HSM), you create a new encrypted cluster and move your data to the new cluster. So I agree C is correct
upvoted 3 times
...
...
...
Nicki1013
Highly Voted 3 years, 7 months ago
Answer: A, C When you use an HSM, you must use client and server certificates to configure a trusted connection between Amazon Redshift and your HSM. Reference link: https://docs.amazonaws.cn/en_us/redshift/latest/mgmt/security-key-management.html To migrate an unencrypted cluster to a cluster encrypted using a hardware security module (HSM), you create a new encrypted cluster and move your data to the new cluster. Reference link: https://docs.aws.amazon.com/redshift/latest/mgmt/changing-cluster-encryption.html
upvoted 15 times
...
tsangckl
Most Recent 1 year, 1 month ago
Bing is answering C and D. By this explanation Option A suggests setting up a trusted connection with HSM using a client and server certificate with automatic key rotation. While this is a valid method for some systems, it’s not directly applicable to Amazon Redshift. Redshift doesn’t support this method for enabling encryption. Option C is correct because Amazon Redshift doesn’t allow you to modify an existing cluster to use HSM encryption. You would need to create a new HSM-encrypted Redshift cluster and migrate the data to it. Option D is also correct. Once the new HSM-encrypted Redshift cluster is set up, you can enable HSM with key rotation through the AWS CLI.
upvoted 1 times
...
NikkyDicky
1 year, 9 months ago
Selected Answer: AC
It's AC
upvoted 1 times
...
pk349
1 year, 12 months ago
AC: I passed the test
upvoted 1 times
...
cloudlearnerhere
2 years, 5 months ago
Selected Answer: AC
Correct answer is A & C as Redshift does not allow encrypting existing cluster using HSM and there needs to be trust connection established between Redshift and HSM. Options B & D are wrong as You can enable encryption when you launch your cluster, or you can modify an unencrypted cluster to use AWS Key Management Service (AWS KMS) encryption. Option E is wrong as it is not valid.
upvoted 2 times
...
rocky48
2 years, 9 months ago
Selected Answer: AC
Answer-A,C
upvoted 1 times
...
Bik000
2 years, 11 months ago
Selected Answer: AC
Answer is A & C
upvoted 1 times
...
jrheen
3 years ago
Answer-A,C
upvoted 1 times
...
aws2019
3 years, 5 months ago
A and C
upvoted 1 times
...
Huy
3 years, 5 months ago
A, C is correct but why Redshift with HSM is asked in 2020? Redshift only works with HSM Classic and new customer can't create HSM classic anymore.
upvoted 3 times
...
Donell
3 years, 5 months ago
Answer: A,C (Similar question is there in Jon Bonso's practice exam).
upvoted 1 times
...
Shraddha
3 years, 5 months ago
B = wrong, to use HSM you have to create new clusters. D = wrong, key rotation is not done by HSM, but Redshift. E = wrong, nonsense. This is a textbook question. https://docs.aws.amazon.com/redshift/latest/mgmt/changing-cluster-encryption.html#migrating-to-an-encrypted-cluster
upvoted 1 times
...
leliodesouza
3 years, 6 months ago
the answers are A and C.
upvoted 1 times
...
jyrajan69
3 years, 6 months ago
Definitely A and C. First answer is from the link provided by testtaker3434, and 2nd answer from the following link https://docs.aws.amazon.com/redshift/latest/mgmt/security-key-management.html
upvoted 3 times
...
lostsoul07
3 years, 6 months ago
A, C is the right answer
upvoted 1 times
...
BillyC
3 years, 6 months ago
A and C are correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago