Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Professional topic 1 question 530 discussion

A company is migrating an application to AWS. It wants to use fully managed services as much as possible during the migration. The company needs to store large, important documents within the application with the following requirements:
✑ The data must be highly durable and available.
✑ The data must always be encrypted at rest and in transit.
✑ The encryption key must be managed by the company and rotated periodically.
Which of the following solutions should the Solutions Architect recommend?

  • A. Deploy the storage gateway to AWS in file gateway mode. Use Amazon EBS volume encryption using an AWS KMS key to encrypt the storage gateway volumes.
  • B. Use Amazon S3 with a bucket policy to enforce HTTPS for connections to the bucket and to enforce server-side encryption and AWS KMS for object encryption.
  • C. Use Amazon DynamoDB with SSL to connect to DynamoDB. Use an AWS KMS key to encrypt DynamoDB objects at rest.
  • D. Deploy instances with Amazon EBS volumes attached to store this data. Use EBS volume encryption using an AWS KMS key to encrypt the data.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
donathon
Highly Voted 2 years, 7 months ago
B. As Storage Gateway is not a managed service
upvoted 28 times
...
dpvnme
Highly Voted 2 years, 7 months ago
B would be my choice
upvoted 10 times
...
SkyZeroZx
Most Recent 10 months, 1 week ago
Selected Answer: B
B. "Highly durable and available" The company needs to store large, important documents S3 is better Option
upvoted 1 times
...
evargasbrz
1 year, 4 months ago
Selected Answer: B
B looks better A-> I don't know if storage gateway to AWS in file gateway mode is able to use Amazon EBS volume.
upvoted 1 times
evargasbrz
1 year, 4 months ago
I think the main point here is "migration", but the option A is confusing, it tells file gateway mode and also volume gateway to use EBS.
upvoted 1 times
...
...
kangtamo
1 year, 10 months ago
Selected Answer: B
Agree with B: S3 HTTPS
upvoted 1 times
...
cldy
2 years, 4 months ago
B. Use Amazon S3 with a bucket policy to enforce HTTPS for connections to the bucket and to enforce server-side encryption and AWS KMS for object encryption.
upvoted 2 times
...
AzureDP900
2 years, 4 months ago
I will pick B.
upvoted 1 times
...
AWSum1
2 years, 5 months ago
B. "Highly durable and available"
upvoted 1 times
...
WhyIronMan
2 years, 5 months ago
I'll go with B
upvoted 1 times
...
KittuCheeku
2 years, 5 months ago
Definitely B
upvoted 1 times
...
Waiweng
2 years, 5 months ago
it's B
upvoted 2 times
...
blackgamer
2 years, 5 months ago
B for sure.
upvoted 1 times
...
KnightVictor
2 years, 5 months ago
Should be B
upvoted 1 times
...
alisyech
2 years, 5 months ago
i go with B
upvoted 1 times
...
awsexamprep47
2 years, 5 months ago
B is the answer All the encryption requirements are satisfied using S-3 bucket policy
upvoted 2 times
...
kiev
2 years, 5 months ago
B for me. In fact I don't even worry to read when a question talks about storage that's fully managed and cost effective, I just for S3
upvoted 4 times
...
Kian1
2 years, 5 months ago
going with B
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...