MLA-C01 exam dumps

MLA-C01 practice question 102 of 458

AWS Certified Machine Learning Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLA-C01 Question 102

Select 2

You are designing a machine learning pipeline for a healthcare application that requires storing sensitive patient data in Amazon S3. Which of the following techniques can you use to ensure the data is encrypted both at rest and in transit?

  1. A

    Use Amazon S3 Server-Side Encryption with AWS Key Management Service (SSE-KMS) for data at rest and enable HTTPS for data in transit.

  2. B

    Use Amazon S3 Server-Side Encryption with a customer-provided key (SSE-C) and transfer data using unencrypted HTTP.

  3. C

    Use Amazon S3 Client-Side Encryption with AWS Key Management Service (KMS) for encryption and HTTPS for secure data transfer.

  4. D

    Enable Amazon S3 default bucket encryption and use Amazon S3 Transfer Acceleration for data in transit.

  5. E

    Store data in plaintext on Amazon S3 and use a Virtual Private Cloud (VPC) to secure access to data.

Show answer and explanation

Correct answers: A, C

Explanation

To protect sensitive data in a healthcare application, it is critical to encrypt data both at rest and in transit. Amazon S3 provides multiple options for encryption at rest, such as SSE-KMS and client-side encryption with AWS KMS. Additionally, enabling HTTPS ensures secure data transfer by encrypting data in transit. Options that fail to secure data in transit or store data in plaintext do not meet the requirements for protecting sensitive information.

  • A. Correct.

    This is a correct option. Amazon S3 Server-Side Encryption with AWS Key Management Service (SSE-KMS) ensures data is encrypted at rest, and enabling HTTPS ensures the data is encrypted in transit.

  • B. Incorrect.

    This is incorrect because transferring data using unencrypted HTTP does not secure data in transit, even though SSE-C encrypts data at rest.

  • C. Correct.

    This is a correct option. Using Amazon S3 Client-Side Encryption with AWS KMS encrypts data before uploading, and HTTPS ensures secure transmission.

  • D. Incorrect.

    This is incorrect because Amazon S3 Transfer Acceleration is used to speed up transfers and does not inherently encrypt data in transit. While default bucket encryption ensures data at rest is encrypted, it does not address encryption in transit.

  • E. Incorrect.

    This is incorrect because storing data in plaintext does not encrypt it at rest, and using a VPC only secures network access but does not encrypt the data.

Timed practice exam

Take a MLA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam