DOP-C02 exam dumps

DOP-C02 practice question 230 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 230

Select 2

Your organization uses Amazon CloudWatch to collect logs and metrics from various AWS services. Due to compliance requirements, you need to ensure that all logs and metrics are encrypted both at rest and in transit. You are tasked with choosing the most appropriate encryption options to meet these requirements. Which of the following options should you implement?

  1. A

    Enable server-side encryption for CloudWatch Logs using AWS Key Management Service (AWS KMS) keys.

  2. B

    Ensure HTTPS is used for all data sent to CloudWatch to encrypt data in transit.

  3. C

    Enable client-side encryption for CloudWatch Logs using a custom encryption library.

  4. D

    Use AWS KMS to encrypt CloudWatch Metrics at rest.

  5. E

    Configure VPC endpoints for CloudWatch Logs and CloudWatch Metrics to ensure private communication.

Show answer and explanation

Correct answers: A, B

Explanation

To meet compliance requirements for encrypting logs and metrics at rest and in transit, you should enable server-side encryption for CloudWatch Logs using AWS KMS keys and ensure HTTPS is used for secure communication to encrypt data in transit. Other options, such as client-side encryption or encrypting metrics with AWS KMS, are either not supported or unnecessary for compliance in this context.

  • A. Correct.

    This is correct. CloudWatch Logs supports server-side encryption using AWS KMS keys to encrypt logs at rest.

  • B. Correct.

    This is correct. HTTPS encrypts data in transit and is the recommended method for secure communication with CloudWatch.

  • C. Incorrect.

    This is incorrect. CloudWatch Logs does not support client-side encryption natively, and implementing a custom encryption library is not necessary or supported for this service.

  • D. Incorrect.

    This is incorrect. CloudWatch Metrics are not stored in a way that supports AWS KMS encryption at rest. AWS handles metric storage securely, but this specific option is not valid.

  • E. Incorrect.

    This is incorrect. While VPC endpoints improve security by keeping traffic within the AWS network, they do not inherently provide encryption for data at rest or in transit.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam