exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 114 discussion

A company currently stores symmetric encryption keys in a hardware security module (HSM). A solutions architect must design a solution to migrate key management to AWS. The solution should allow for key rotation and support the use of customer provided keys.
Where should the key material be stored to meet these requirements?

  • A. Amazon S3
  • B. AWS Secrets Manager
  • C. AWS Systems Manager Parameter store
  • D. AWS Key Management Service (AWS KMS)
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Asad85
Highly Voted 3 years, 8 months ago
Should be D
upvoted 33 times
rey123
3 years, 7 months ago
Why? KMS --> Manages all the keys to encrypt/decrypt stuff. Secrets Manager --> Manages passwords that are encrypted with KMS. The questions says that the HSM contains encryption keys not passwords for databases or other services, as a consequence it has to be D.
upvoted 37 times
anverdor
3 years, 7 months ago
Secret manager doesnt support asymetric Keys
upvoted 6 times
aguy9
3 years, 6 months ago
It’s not asking secrets manager to support asymmetric keys. It specifies symmetric keys and “Leveraging a service like AWS Secrets Manager, to outsource secured storage and life-cycle management of secrets (like passwords, API keys, tokens, encryption keys, etc.) is becoming quite commonplace.” https://medium.com/swlh/storing-encryption-keys-in-aws-secrets-manager-8b2be87a891e
upvoted 2 times
...
...
...
kuman
3 years, 6 months ago
Answer is D. Keys are used for encryption. Secrets Manager is to store secrets used for authentication, not encryption.
upvoted 16 times
...
...
sgupta_22
Highly Voted 3 years, 7 months ago
D is correct. Yes. You can choose to have AWS KMS automatically rotate CMKs every year, provided that those keys were generated within AWS KMS HSMs. Automatic key rotation is not supported for imported keys, asymmetric keys, or keys generated in an AWS CloudHSM cluster using the AWS KMS custom key store feature. If you choose to import keys to AWS KMS or asymmetric keys or use a custom key store, you can manually rotate them by creating a new CMK and mapping an existing key alias from the old CMK to the new CMK. https://aws.amazon.com/kms/faqs/#:~:text=Yes.,KMS%20custom%20key%20store%20feature.
upvoted 13 times
...
bighedgedog
Most Recent 2 years, 11 months ago
Selected Answer: D
D - Correct. KMS generates and manages encryption keys. B - Incorrect. Secret Manager is used to store credentials / passwords, etc (can use KMS to encrypt the credentials). https://aws.amazon.com/secrets-manager/ https://docs.aws.amazon.com/kms/latest/developerguide/overview.html https://acloudguru.com/forums/aws-certified-cloud-practitioner/key-management-service-kms-vs-secrets-manager
upvoted 1 times
...
tin2022
3 years, 4 months ago
B Where should critical material be housed means stored. So AWS Secrets Manager
upvoted 1 times
...
tin2022
3 years, 4 months ago
B Where should critical material be housed means stored, so AWS Secrets Manager
upvoted 1 times
...
muhsin
3 years, 5 months ago
B I think the question is about Where should critical material be housed not the features of Key services.
upvoted 2 times
...
Siraf
3 years, 5 months ago
Answer is B. AWS Secrets Manager enables you to easily rotate...
upvoted 2 times
...
karthisena
3 years, 6 months ago
AWS Secrets Manager • Newer service, meant for storing secrets • Capability to force rotation of secrets every X days • Automate generation of secrets on rotation (uses Lambda) • Integration with Amazon RDS (MySQL, PostgreSQL, Aurora) • Secrets are encrypted using KMS
upvoted 2 times
...
Veny
3 years, 6 months ago
Secrets Manager stores the encrypted data key with the protected secret data. Whenever the secret needs decryption, Secrets Manager requests AWS KMS to decrypt the data key, which Secrets Manager then uses to decrypt the protected secret data.
upvoted 2 times
...
tinyshare
3 years, 6 months ago
Should be B: Secrets Manager Secrets Manager is used to store secrets including credentials and keys (Other types of secrets) https://miro.medium.com/max/2400/1*iHF6qkdIwmr4mGKHb4HHCg.png
upvoted 1 times
tinyshare
3 years, 6 months ago
Store, rotation: Secrets Manager Encryption, control, manage: KMS
upvoted 2 times
...
...
vajira
3 years, 6 months ago
AWS Secrets Manager helps you protect secrets needed to access your applications, services, and IT resources. The service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle. https://aws.amazon.com/secrets-manager/ B
upvoted 3 times
...
syu31svc
3 years, 6 months ago
100% is D A and C are wrong for sure B is for API keys as per link https://aws.amazon.com/secrets-manager/
upvoted 2 times
...
KK_uniq
3 years, 6 months ago
KMS is needed for cloudhsm D for sure
upvoted 2 times
...
Yogi
3 years, 6 months ago
Ans = D KMS permits key rotation
upvoted 2 times
...
ashok1234567890
3 years, 6 months ago
DDDDDDDDDDDDDDDDDDDDD
upvoted 2 times
...
Ankitrathi85
3 years, 6 months ago
B right
upvoted 1 times
...
NSF
3 years, 6 months ago
Apologies for the wrong post above, I meant to say following statement on the below link compelled me to go for ANSWER B https://docs.aws.amazon.com/kms/latest/developerguide/services-secrets-manager.html Secrets Manager integrates with AWS Key Management Service (AWS KMS) to encrypt every version of every secret with a unique data key that is protected by an AWS KMS customer master key (CMK).
upvoted 1 times
seasky
3 years, 6 months ago
backbone is KMS then
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago