exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 715 discussion

A company is building an application in the AWS Cloud. The application will store data in Amazon S3 buckets in two AWS Regions. The company must use an
AWS Key Management Service (AWS KMS) customer managed key to encrypt all data that is stored in the S3 buckets. The data in both S3 buckets must be encrypted and decrypted with the same KMS key. The data and the key must be stored in each of the two Regions.
Which solution will meet these requirements with the LEAST operational overhead?

  • A. Create an S3 bucket in each Region. Configure the S3 buckets to use server-side encryption with Amazon S3 managed encryption keys (SSE-S3). Configure replication between the S3 buckets.
  • B. Create a customer managed multi-Region KMS key. Create an S3 bucket in each Region. Configure replication between the S3 buckets. Configure the application to use the KMS key with client-side encryption.
  • C. Create a customer managed KMS key and an S3 bucket in each Region. Configure the S3 buckets to use server-side encryption with Amazon S3 managed encryption keys (SSE-S3). Configure replication between the S3 buckets.
  • D. Create a customer managed KMS key and an S3 bucket in each Region. Configure the S3 buckets to use server-side encryption with AWS KMS keys (SSE- KMS). Configure replication between the S3 buckets.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BECAUSE
1 year, 11 months ago
Selected Answer: D
D is the answer
upvoted 1 times
...
furytara
2 years, 1 month ago
should be D. B is out because client-side encryption is incorrect. Why D explained here https://catalog.workshops.aws/s3multiregionaccesspoints/en-US/module-4
upvoted 1 times
...
wombles
2 years, 4 months ago
https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html#:~:text=imported%20key%20material-,You%20cannot%20create%20multi%2DRegion%20keys%20in%20a%20custom%20key%20store.,-Topics
upvoted 1 times
...
SVGoogle89
2 years, 6 months ago
D. You cannot create multi-Region keys in a custom key store.
upvoted 1 times
...
jxp09
2 years, 7 months ago
ans is D
upvoted 1 times
...
rodriiviru
2 years, 7 months ago
Selected Answer: B
https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html
upvoted 1 times
envest
2 years, 7 months ago
IMO: new feature with simplified & efficient client side encrypt for DR. Otherwise, client-side encrypt would be too complex. I agree on B.
upvoted 1 times
...
...
guptatrng
2 years, 8 months ago
I think it is D...
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago