exam questions

Exam AWS Certified Database - Specialty All Questions

View all questions & answers for the AWS Certified Database - Specialty exam

Exam AWS Certified Database - Specialty topic 1 question 116 discussion

Exam question from Amazon's AWS Certified Database - Specialty
Question #: 116
Topic #: 1
[All AWS Certified Database - Specialty Questions]

A company uses Amazon Aurora for secure financial transactions. The data must always be encrypted at rest and in transit to meet compliance requirements.
Which combination of actions should a database specialist take to meet these requirements? (Choose two.)

  • A. Create an Aurora Replica with encryption enabled using AWS Key Management Service (AWS KMS). Then promote the replica to master.
  • B. Use SSL/TLS to secure the in-transit connection between the financial application and the Aurora DB cluster.
  • C. Modify the existing Aurora DB cluster and enable encryption using an AWS Key Management Service (AWS KMS) encryption key. Apply the changes immediately.
  • D. Take a snapshot of the Aurora DB cluster and encrypt the snapshot using an AWS Key Management Service (AWS KMS) encryption key. Restore the snapshot to a new DB cluster and update the financial application database endpoints.
  • E. Use AWS Key Management Service (AWS KMS) to secure the in-transit connection between the financial application and the Aurora DB cluster.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
shantest1
Highly Voted 3 years, 7 months ago
B and D.
upvoted 14 times
...
tugboat
Highly Voted 3 years, 2 months ago
Selected Answer: BD
Per - https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/Overview.Encryption.html Not A as - You can't create an encrypted Aurora Replica from an unencrypted Aurora DB cluster. You can't create an unencrypted Aurora Replica from an encrypted Aurora DB cluster. B is good for in-transit replication Not C as - You can't convert an unencrypted DB cluster to an encrypted one. D as - You can restore an unencrypted snapshot to an encrypted Aurora DB cluster. To do this, specify a KMS key when you restore from the unencrypted snapshot. Not E as - KMS does not perform encryption for data in transit or in motion. If you want to encrypt data while in transit, then you would need to use a different method such as SSL. So, B and D is correct.
upvoted 6 times
...
redman50
Most Recent 2 years, 1 month ago
Selected Answer: AC
In Aurora you can encrypt at rest without copying the snapshot. So A and C for sure
upvoted 1 times
Piccaso
2 years, 1 month ago
https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/Overview.Encryption.html#Overview.Encryption.Limitations
upvoted 1 times
...
...
dougporto1988
2 years, 2 months ago
Selected Answer: BD
I reckon is B and D
upvoted 1 times
...
lunt
3 years ago
Selected Answer: BD
B and D. D is right. Take snapshot of cluster > and (keyword here) > enable encryption. You cannot take a snapshot and encrypt it at the same time, this where the 'and' comes into play, you can encrypt just a snapshot + you can encrypt the snapshot on restore.
upvoted 2 times
...
novice_expert
3 years ago
Selected Answer: BD
B. SSL/TLS is good for in-transit replication D. as - You can restore an unencrypted snapshot to an encrypted Aurora DB cluster
upvoted 2 times
novice_expert
3 years ago
D. as - You can NOT restore an unencrypted snapshot to an encrypted Aurora DB cluster
upvoted 1 times
...
...
kped21
3 years, 2 months ago
B,D C: Wrong, you cannot modify an unencrypted to encrypted
upvoted 3 times
...
awsmonster
3 years, 4 months ago
A and B .. https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-replicas-adding.html D is incorrect: https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/USER_CopySnapshot.html For Amazon Aurora DB cluster snapshots, you can't encrypt an unencrypted DB cluster snapshot when you copy the snapshot.
upvoted 4 times
...
ChauPhan
3 years, 6 months ago
B and D is correct
upvoted 1 times
...
Hits_23
3 years, 6 months ago
B and D are correct choice.
upvoted 1 times
...
Jaypdv
3 years, 7 months ago
BD B. is obvious. For D. I thought it's possible to directly restore the unencrypted snapshot into an encrypted cluster so somehow one step looks unnecessary. But A, C and E are incorrect so I pick D. by default
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago