exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 5 discussion

A company is storing data on Amazon Simple Storage Service (S3). The company's security policy mandates that data is encrypted at rest.
Which of the following methods can achieve this? (Choose three.)

  • A. Use Amazon S3 server-side encryption with AWS Key Management Service managed keys.
  • B. Use Amazon S3 server-side encryption with customer-provided keys.
  • C. Use Amazon S3 server-side encryption with EC2 key pair.
  • D. Use Amazon S3 bucket policies to restrict access to the data at rest.
  • E. Encrypt the data on the client-side before ingesting to Amazon S3 using their own master key.
  • F. Use SSL to encrypt the data while in transit to Amazon S3.
Show Suggested Answer Hide Answer
Suggested Answer: ABE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ppshein
Highly Voted 3 years, 7 months ago
My choice is A,B,E
upvoted 9 times
nitinz
3 years, 6 months ago
only ABE does encryption at rest.
upvoted 2 times
...
...
amministrazione
Most Recent 8 months, 3 weeks ago
A. Use Amazon S3 server-side encryption with AWS Key Management Service managed keys. B. Use Amazon S3 server-side encryption with customer-provided keys. E. Encrypt the data on the client-side before ingesting to Amazon S3 using their own master key.
upvoted 1 times
...
kuongnp
9 months, 4 weeks ago
Selected Answer: ABE
A, B, E is correct
upvoted 1 times
...
andersoncarvalho
1 year, 6 months ago
Selected Answer: ABE
You can either use AWS managed key or Customer Managed Key to perform Server Side S3 bucket encryption, but no EC2 key-pair. EC2 key-pair is used to authenticate via SSH, not encrypt. You can also use your own methods to encrypt the data before upload to S3.
upvoted 1 times
...
ajchi1980
1 year, 10 months ago
Wrong answers: C. Use Amazon S3 server-side encryption with EC2 key pair: Amazon S3 does not support using EC2 key pairs for server-side encryption. EC2 key pairs are primarily used for securely accessing EC2 instances. D. Use Amazon S3 bucket policies to restrict access to the data at rest: Bucket policies are used to control access to objects stored in S3 buckets, but they do not provide encryption at rest. Encryption at rest should be handled through one of the server-side encryption options mentioned above. Option F is also incorrect: F. Use SSL to encrypt the data while in transit to Amazon S3: SSL (Secure Sockets Layer) encryption is used to secure the data during transit between the client and the S3 service. While it helps protect data in transit, it does not provide encryption at rest, which is specifically required by the company's security policy.
upvoted 1 times
...
ajchi1980
1 year, 10 months ago
Selected Answer: ABE
The three methods that can achieve data encryption at rest on Amazon S3 are: A. Use Amazon S3 server-side encryption with AWS Key Management Service (KMS) managed keys: This method enables automatic encryption of data at rest using AWS KMS. The encryption keys are managed by AWS, providing a convenient and secure solution. B. Use Amazon S3 server-side encryption with customer-provided keys: This method allows you to provide your own encryption keys to encrypt the data at rest. You can manage the keys yourself and have full control over the encryption process. E. Encrypt the data on the client-side before ingesting to Amazon S3 using their own master key: This method involves encrypting the data on the client-side before uploading it to Amazon S3. You can use your own master key or encryption algorithm to ensure the data is encrypted before it reaches the S3 service.
upvoted 2 times
...
SkyZeroZx
1 year, 11 months ago
Selected Answer: ABE
My choice is A,B,E
upvoted 1 times
...
iamRohanKaushik
2 years, 1 month ago
Selected Answer: ABE
ABE is correct
upvoted 1 times
...
gameoflove
2 years, 1 month ago
Selected Answer: ABE
A, B & E are only suitable right answer
upvoted 1 times
...
TigerInTheCloud
2 years, 5 months ago
Selected Answer: ABE
C, D, and F are wrong
upvoted 1 times
...
emmanuelodenyire
2 years, 7 months ago
Selected Answer: ABE
I see only these support encryption at rest
upvoted 1 times
...
skywalker
2 years, 8 months ago
I will go for A,B,E
upvoted 1 times
...
michaelbaib
2 years, 11 months ago
dont understand why encrypt 3 times??
upvoted 2 times
...
bluesmile979
3 years, 1 month ago
vote ABE
upvoted 1 times
...
cldy
3 years, 5 months ago
A. Use Amazon S3 server-side encryption with AWS Key Management Service managed keys. B. Use Amazon S3 server-side encryption with customer-provided keys. E. Encrypt the data on the client-side before ingesting to Amazon S3 using their own master key.
upvoted 1 times
...
Akhil254
3 years, 6 months ago
ABE Correct
upvoted 1 times
...
kidd5
3 years, 6 months ago
ABE is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago