DVA-C02 exam dumps

DVA-C02 practice question 162 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 162

Single answer

You are developing an application hosted on Amazon EC2 instances that stores sensitive customer data in an Amazon S3 bucket. To meet compliance requirements, all data must be encrypted at rest. You also want to maintain control over the encryption keys while minimizing operational overhead. Which solution should you implement?

  1. A

    Use Amazon S3 server-side encryption with AWS Key Management Service (SSE-KMS).

  2. B

    Use Amazon S3 server-side encryption with customer-provided keys (SSE-C).

  3. C

    Use Amazon S3 client-side encryption with keys managed by the AWS Key Management Service (AWS KMS).

  4. D

    Use Amazon S3 server-side encryption with Amazon S3-managed keys (SSE-S3).

Show answer and explanation

Correct answer: A

Explanation

To meet the compliance requirement of maintaining control over encryption keys while ensuring data is encrypted at rest, AWS S3 server-side encryption with AWS KMS (SSE-KMS) is the ideal solution. SSE-KMS integrates with AWS Key Management Service, allowing you to manage the encryption keys easily without having to handle the operational burden of key storage and rotation. Other options either add unnecessary complexity or fail to meet the compliance requirement for key control.

  • A. Correct.

    This is the correct answer. SSE-KMS allows you to encrypt data at rest in S3 using AWS KMS keys, giving you control over key management while reducing operational complexity.

  • B. Incorrect.

    This is incorrect because while SSE-C allows you to manage your own encryption keys, it requires you to implement and maintain the key management process, which increases operational overhead.

  • C. Incorrect.

    This is incorrect because client-side encryption requires you to handle encryption and decryption on your own, including key management, which adds significant complexity.

  • D. Incorrect.

    This is incorrect because SSE-S3 uses Amazon S3-managed keys, which do not provide you with direct control over the encryption keys, failing the compliance requirement for key control.

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam