DVA-C02 exam dumps

DVA-C02 practice question 184 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 184

Single answer

Your application stores sensitive data in an Amazon S3 bucket. To meet compliance requirements, the data must be encrypted at rest. You are deciding between using client-side encryption and server-side encryption. Which of the following is a key difference between these two encryption methods?

  1. A

    With client-side encryption, the encryption and decryption keys are managed by AWS.

  2. B

    With server-side encryption, the encryption process happens on the AWS servers after data is uploaded.

  3. C

    Client-side encryption requires enabling a specific setting in the S3 bucket configuration.

  4. D

    Server-side encryption requires the application to manage and provide encryption keys to AWS.

Show answer and explanation

Correct answer: B

Explanation

The key difference between client-side encryption and server-side encryption lies in where the encryption process occurs and who manages the encryption keys. Client-side encryption involves the client encrypting data before uploading it to AWS, and the client is responsible for key management. Server-side encryption, on the other hand, encrypts data after it is uploaded to AWS servers, with AWS managing the encryption process and keys unless a customer-provided key option is used.

  • A. Incorrect.

    Incorrect: In client-side encryption, the encryption and decryption keys are managed by the client, not AWS. The client is responsible for generating, managing, and securely storing the keys.

  • B. Correct.

    Correct: Server-side encryption encrypts data after it is uploaded to AWS servers. AWS manages the encryption process and can use AWS-managed or customer-provided keys.

  • C. Incorrect.

    Incorrect: Client-side encryption is implemented entirely by the client and does not involve enabling any settings in the S3 bucket configuration.

  • D. Incorrect.

    Incorrect: In server-side encryption, AWS handles the encryption and decryption process, including managing keys (unless a customer-provided key is used). The application does not need to provide keys unless explicitly using server-side encryption with customer-provided keys (SSE-C).

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam