SAA-C03 exam dumps

SAA-C03 practice question 2 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 2

Select 3

Your company is building a web application on AWS that stores sensitive customer data in an Amazon S3 bucket. The application is backed by an Amazon RDS database. You are tasked with designing a secure architecture to ensure compliance with security best practices. Which combination of steps should you take to secure the data both in transit and at rest?

  1. A

    Enable server-side encryption (SSE) on the Amazon S3 bucket using AWS Key Management Service (KMS).

  2. B

    Use SSL/TLS to encrypt data in transit between the application and Amazon RDS.

  3. C

    Ensure the Amazon S3 bucket is publicly accessible to simplify application access.

  4. D

    Enable Amazon RDS encryption at rest using AWS-managed keys.

  5. E

    Set up an IAM policy to allow all users full access to the Amazon S3 bucket for testing purposes.

Show answer and explanation

Correct answers: A, B, D

Explanation

To design a secure architecture for storing sensitive customer data on AWS, you must ensure both data at rest and data in transit are properly protected. This includes enabling encryption for S3 and RDS to secure data at rest and using SSL/TLS to secure data in transit. Avoiding risky configurations like public bucket access and overly permissive IAM policies is also critical for maintaining a secure environment.

  • A. Correct.

    Correct: Enabling server-side encryption (SSE) with AWS KMS ensures that data stored in the S3 bucket is encrypted at rest. This is a critical security measure for protecting sensitive data.

  • B. Correct.

    Correct: Using SSL/TLS ensures that data in transit between the application and Amazon RDS is encrypted, preventing interception and unauthorized access during transmission.

  • C. Incorrect.

    Incorrect: Making the S3 bucket publicly accessible is a significant security risk. Sensitive customer data should never be exposed publicly.

  • D. Correct.

    Correct: Enabling RDS encryption at rest with AWS-managed keys ensures that data stored in the database is encrypted, which is crucial for meeting security best practices.

  • E. Incorrect.

    Incorrect: Allowing all users full access to the S3 bucket using an overly permissive IAM policy violates the principle of least privilege and exposes sensitive data to unauthorized access.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam