DVA-C02 exam dumps

DVA-C02 practice question 170 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 170

Select 3

You are developing an application that stores sensitive customer data in Amazon S3. The application must ensure that the data is encrypted both at rest and during transit. Which combination of actions should you take to meet these requirements?

  1. A

    Enable server-side encryption (SSE) on the S3 bucket to encrypt data at rest.

  2. B

    Use HTTPS for all communications between the application and Amazon S3 to encrypt data in transit.

  3. C

    Enable default bucket versioning to automatically encrypt data at rest.

  4. D

    Use a customer-managed CMK in AWS Key Management Service (KMS) for server-side encryption.

  5. E

    Use AWS Secrets Manager to encrypt the data at rest in the S3 bucket.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure encryption at rest and in transit for sensitive data stored in Amazon S3, you should enable server-side encryption (SSE) for data at rest and use HTTPS for secure communication to encrypt data in transit. Additionally, using a customer-managed CMK in AWS KMS for SSE provides enhanced control over encryption keys. Other options, such as bucket versioning and AWS Secrets Manager, do not directly address encryption requirements for data stored in S3.

  • A. Correct.

    Correct. Enabling server-side encryption (SSE) ensures that your data is encrypted at rest while stored in the S3 bucket.

  • B. Correct.

    Correct. Using HTTPS ensures that data is encrypted in transit between your application and S3.

  • C. Incorrect.

    Incorrect. Bucket versioning is used to maintain multiple versions of objects, but it does not provide encryption for data at rest.

  • D. Correct.

    Correct. Using a customer-managed CMK in AWS KMS for server-side encryption adds an additional layer of control to encrypt data at rest.

  • E. Incorrect.

    Incorrect. AWS Secrets Manager is used to manage secrets like database credentials or API keys, not for encrypting data in S3.

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam