exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 634 discussion

Exam question from Amazon's AWS-SysOps
Question #: 634
Topic #: 1
[All AWS-SysOps Questions]

A company has adopted a security policy that requires all customer data to be encrypted at rest. Currently, customer data is stored on a central Amazon EFS file system and accessed by a number of different applications from Amazon EC2 instances.
How can the SysOps Administrator ensure that all customer data stored on the EFS file system meets the new requirement?

  • A. Update the EFS file system settings to enable server-side encryption using AES-256.
  • B. Create a new encrypted EFS file system and copy the data from the unencrypted EFS file system to the new encrypted EFS file system.
  • C. Use AWS CloudHSM to encrypt the files directly before storing them in the EFS file system.
  • D. Modify the EFS file system mount options to enable Transport Layer Security (TLS) on each of the EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 7 months ago
B should be correct If you want to delete an unencrypted-at-rest file system but want to retain the data, first create a new encrypted-at-rest file system. Next, copy the data over to the new encrypted-at-rest file system. https://docs.aws.amazon.com/efs/latest/ug/efs-enforce-encryption.html
upvoted 22 times
...
coolboylqy
Highly Voted 2 years, 7 months ago
should be B. https://docs.aws.amazon.com/efs/latest/ug/efs-enforce-encryption.html
upvoted 12 times
...
albert_kuo
Most Recent 10 months ago
Selected Answer: B
By creating a new encrypted EFS file system, you can ensure that all data stored on it is encrypted at rest. When creating the encrypted EFS file system, you can enable the encryption option, which will encrypt the data using AWS Key Management Service (KMS) and a customer-managed CMK (Customer Master Key). After creating the new encrypted EFS file system, the data from the existing unencrypted EFS file system should be copied to the new encrypted file system. This can be done using various methods, such as using the EFS-to-EFS backup solution, rsync, or other data migration tools.
upvoted 1 times
...
abhishek_m_86
2 years, 5 months ago
B. Create a new encrypted EFS file system and copy the data from the unencrypted EFS file system to the new encrypted EFS file system. Seem correct
upvoted 2 times
...
Chirantan
2 years, 6 months ago
B is correct as you can not modify EFS for encryption
upvoted 2 times
...
jackdryan
2 years, 6 months ago
I'll go with B
upvoted 2 times
...
MFDOOM
2 years, 6 months ago
Ans is B I created 2 EFS in the console to try it out myself. Once you create an unencypted EFS you cannot switch it to encrpted later on. https://docs.aws.amazon.com/efs/latest/ug/efs-enforce-encryption.html
upvoted 2 times
...
gilbertlelancelo
2 years, 6 months ago
A. Update the EFS file system settings to enable server-side encryption using AES-256. https://docs.aws.amazon.com/efs/latest/ug/encryption-at-rest.html
upvoted 1 times
gilbertlelancelo
2 years, 6 months ago
B Sorry
upvoted 2 times
...
...
waterzhong
2 years, 6 months ago
should be B.
upvoted 1 times
...
MrDEVOPS
2 years, 6 months ago
Encryption thumb rule:- S3 can be encrypted any time before and after creation. EBS ,RDS ,etc should be encrypted while creating only. So ANS:- B
upvoted 6 times
...
ezat
2 years, 7 months ago
B is correct
upvoted 1 times
...
aksliveswithaws
2 years, 7 months ago
B is correct upvoted for saumenP reference and explanation.
upvoted 2 times
...
mukeshs
2 years, 7 months ago
It should be. You cannot encrypt an existing EFS
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago