DOP-C02 exam dumps

DOP-C02 practice question 313 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 313

Select 2

You are managing an application that is running on Amazon ECS using the Fargate launch type. The application processes sensitive customer data, and compliance requirements mandate that all log data must remain encrypted at rest. You need to ensure that the logs generated by the application are securely stored. Which combination of steps should you take to meet this requirement?

  1. A

    Configure Amazon CloudWatch Logs for the ECS task and enable encryption using a KMS key.

  2. B

    Use an S3 bucket to store logs and enable server-side encryption with Amazon S3-managed keys (SSE-S3).

  3. C

    Configure Amazon CloudWatch Logs for the ECS task and enable log group encryption using a customer-managed KMS key.

  4. D

    Use an S3 bucket to store logs and enable server-side encryption with a customer-managed KMS key (SSE-KMS).

  5. E

    Enable encryption in transit for logs streamed to Amazon CloudWatch Logs.

Show answer and explanation

Correct answers: C, D

Explanation

To meet the compliance requirement of encrypting logs at rest, you need to ensure that logs are encrypted using customer-managed encryption keys. In this scenario, enabling log group encryption in CloudWatch Logs with a customer-managed KMS key or storing logs in an S3 bucket with SSE-KMS are both valid solutions. These options ensure that the sensitive log data is securely encrypted and meet the compliance requirements.

  • A. Incorrect.

    While CloudWatch Logs is a valid destination for logs, enabling encryption using a KMS key must be done on the log group, not directly for the ECS task. Therefore, this option is incorrect.

  • B. Incorrect.

    Using S3 with SSE-S3 provides encryption, but it does not meet the requirement for customer-managed encryption keys, which is often necessary for compliance in sensitive scenarios. Therefore, this option is incorrect.

  • C. Correct.

    This is correct because enabling log group encryption in CloudWatch Logs using a customer-managed KMS key ensures that the logs are encrypted at rest with compliance to customer-controlled encryption key management.

  • D. Correct.

    This is correct because storing the logs in an S3 bucket with server-side encryption using a customer-managed KMS key ensures that the logs are encrypted at rest and compliance requirements are met.

  • E. Incorrect.

    Encryption in transit is important but does not satisfy the requirement of encrypting logs at rest. Therefore, this option is incorrect.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam