SAA-C03 exam dumps

SAA-C03 practice question 4 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 4

Select 3

A company is designing a web application that processes sensitive customer information. The application will be hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). As part of the security requirements, the application must ensure that sensitive data is encrypted both in transit and at rest. Which of the following steps should the company take to meet these requirements?

  1. A

    Use an SSL/TLS certificate on the Application Load Balancer to enforce HTTPS connections.

  2. B

    Enable server-side encryption for the S3 bucket where sensitive data backups are stored.

  3. C

    Use an IAM role to allow the EC2 instances to access the sensitive data without hardcoding credentials.

  4. D

    Configure the EC2 instances to use an encrypted Amazon Elastic Block Store (Amazon EBS) volume.

  5. E

    Set up VPC Flow Logs to monitor and log all network traffic for the EC2 instances.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the requirements of encrypting sensitive data in transit and at rest, the company must enforce HTTPS connections on the ALB with SSL/TLS, enable server-side encryption for S3 buckets, and use encrypted EBS volumes for EC2 instances. While IAM roles and VPC Flow Logs are security best practices, they do not directly address the encryption requirements specified in the scenario.

  • A. Correct.

    Using an SSL/TLS certificate on the Application Load Balancer ensures that all data in transit between clients and the application is encrypted, satisfying the encryption-in-transit requirement.

  • B. Correct.

    Enabling server-side encryption for the S3 bucket ensures that data at rest in the S3 bucket is encrypted, which is part of the requirement for securing sensitive data.

  • C. Incorrect.

    While using an IAM role is good for security and avoiding hardcoding credentials, it does not directly address the encryption of data in transit or at rest.

  • D. Correct.

    Configuring the EC2 instances with encrypted Amazon EBS volumes ensures that sensitive data stored on the instance is encrypted at rest, meeting the data-at-rest encryption requirement.

  • E. Incorrect.

    Setting up VPC Flow Logs is useful for monitoring and troubleshooting, but it does not contribute to meeting the encryption-in-transit or encryption-at-rest requirements.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam