exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 357 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 357
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security audit reveals that several Amazon Elastic Block Store (Amazon EBS) volumes in a company's production account are not encrypted. The unencrypted EBS volumes are attached to Amazon EC2 instances that are provisioned with an Auto Scaling group and a launch template.

A security engineer must implement a solution to ensure that all EBS volumes are encrypted now and in the future.

Which solution will meet these requirements?

  • A. Update the launch template by setting the Encrypted flag for all EBS volumes to true, Use the Auto Scaling group's instance refresh feature to replace existing instances with new instances.
  • B. Create a new launch template from the old launch template. Set the Encrypted flag for all EBS volumes to true. Update the Auto Scaling group to use the new version of the launch template. Wait for the Auto Scaling group to replace all the old instances that have unencrypted EBS volumes.
  • C. Use the Amazon EC2 console to enable encryption of new EBS volumes by default for each AWS Region that the company uses. Use the Auto Scaling group's instance refresh feature to replace existing instances with new instances.
  • D. Use the Amazon EC2 console to enable encryption of new EBS volumes by default for each AWS Region that the company uses. Update this setting so that Auto Scaling groups will automatically replace existing instances with new instances.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sse69
Highly Voted 2 years, 6 months ago
Selected Answer: C
C https://docs.aws.amazon.com/autoscaling/ec2/userguide/asg-instance-refresh.html https://aws.amazon.com/premiumsupport/knowledge-center/ebs-automatic-encryption/ Turning on encryption by default doesn't change any existing unencrypted or encrypted resources. It encrypts only volumes and snapshot copies that you create after turning on default encryption.
upvoted 6 times
...
Arad
Most Recent 1 year ago
Selected Answer: C
I believe C is the right answer.
upvoted 1 times
...
yorkicurke
1 year, 6 months ago
Selected Answer: B
enabling encryption by default in the EC2 console does not apply to existing EBS volumes. It only applies to new EBS volumes that are created after the setting is enabled. And in question it was specifically asked 'Now'. so
upvoted 1 times
...
Shenannigan
1 year, 9 months ago
Selected Answer: C
based on the statement: "A security engineer must implement a solution to ensure that all EBS volumes are encrypted now and in the future" I am picking C as other volumes could be spun up outside of the ASG that were un-encrypted and B only addresses the ASG.
upvoted 1 times
...
vherman
2 years ago
Selected Answer: C
C is correct
upvoted 1 times
...
Green53
2 years ago
Selected Answer: C
Seems split between B and C. B certainly sounds feasible, but I would elimintate it simply because you're waiting for the ASG to replace all the old instances. I'd much prefer to use the instance refresh feature to replace the instances instantly. C sounds like the better option, since it will not only cover the instances in the ASG, but all other instances by default. https://repost.aws/knowledge-center/ebs-automatic-encryption If C wasn't an option, I'd likely go A though.
upvoted 2 times
...
michele_scar
2 years ago
Selected Answer: B
With B you solve the question without entropy of other configurations
upvoted 1 times
...
Tofu13
2 years, 1 month ago
Selected Answer: B
sse69 links and explanation are both fine. However, this leads to Answer B as encryption by default only applies to future volumes. But we want all of them to be encrypted now as well. B takes some time until all unencrypted volumes are replaced, but its the only answer left.
upvoted 1 times
...
isokalau
2 years, 2 months ago
Selected Answer: B
Option A is incorrect because updating the launch template will not affect the existing instances with unencrypted EBS volumes. The instance refresh feature only replaces instances that are in the Auto Scaling group, but it does not change the EBS volume encryption. Option C is incorrect because it only applies to new EBS volumes and not to the existing unencrypted EBS volumes attached to the instances. Option D is also incorrect because it sets encryption of new EBS volumes to be enabled by default for each region, but it does not address the existing unencrypted EBS volumes attached to the instances.
upvoted 3 times
isokalau
2 years, 2 months ago
Therefore, the most appropriate solution is to create a new launch template that has encryption enabled for all EBS volumes and update the Auto Scaling group to use the new launch template. The Auto Scaling group will then replace all the old instances with new instances that have encrypted EBS volumes.
upvoted 1 times
...
...
c73bf38
2 years, 3 months ago
Selected Answer: B
Set the Encrypted flag for all EBS volumes to true.
upvoted 2 times
...
Artaggedon
2 years, 3 months ago
Selected Answer: C
D and B are INCORRECT since the Auto Scaling Groups will not inmediatelly replace the unencrypted ELBs. A is INCORRECT since every ELBs aside from the ones launched from template will be able stay unencrypted. C is the only one CORRECT since you cover the entire Region and you don't have to wait for the ELBs to be replaced.
upvoted 2 times
...
roguecloud
2 years, 4 months ago
Selected Answer: C
Going with C based on Instance Refresh documentation provided. Also the 'wait' is a sign that B is not correct. I've seen many ASGs in Production that do not change for extended periods of time.
upvoted 3 times
...
ygen
2 years, 4 months ago
Selected Answer: B
Option C doesn't answer a case that in the future the company decide to use a new region.
upvoted 2 times
ygen
2 years, 4 months ago
BTW, can someone please explain why option A is not valid?
upvoted 1 times
...
...
Smartphone
2 years, 5 months ago
Guys read the question carefully "implement a solution to ensure that all EBS volumes are encrypted now and in the future".. By using the option B the instances will be launched with encryption for this autoscaling group.. But remember, in FUTURE, if you launch any instance then by default that EBS volume will NOT be encrypted... But the Option C ensures that any EBS volume launched in FUTURE will be encrypted and as well as it will also encrypt the volume of current autoscaling group. Hence the correct answer is C.
upvoted 4 times
...
secdaddy
2 years, 5 months ago
Either B or C should work. The requirement says 'now'. B says wait != now whereas C = instance refresh = now so I guess C
upvoted 2 times
...
Teknoklutz
2 years, 6 months ago
Selected Answer: B
An instance refresh can be helpful when you have a new Amazon Machine Image (AMI) or a new user data script. To use an instance refresh, first create a new launch template that specifies the new AMI or user data script. Then, start an instance refresh to begin updating the instances in the group immediately. So its B
upvoted 2 times
...
Fyssy
2 years, 6 months ago
Selected Answer: B
https://docs.aws.amazon.com/autoscaling/ec2/userguide/change-launch-config.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...