SAA-C03 exam dumps

SAA-C03 practice question 65 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 65

Select 2

A company is migrating its on-premises data to Amazon S3. The company requires that the data be encrypted at rest and wants to ensure that only their internal compliance team manages the encryption keys. Additionally, they need to track access to the data for audit purposes. Which combination of solutions should the company implement to meet these requirements?

  1. A

    Use Server-Side Encryption with S3-Managed Keys (SSE-S3) for data encryption at rest.

  2. B

    Use Server-Side Encryption with AWS Key Management Service (SSE-KMS) with a customer-managed CMK.

  3. C

    Enable S3 Server Access Logging to track requests made to the bucket.

  4. D

    Enable S3 Object Lock to prevent any modifications to the data.

  5. E

    Use Client-Side Encryption and manage the encryption keys on-premises.

Show answer and explanation

Correct answers: B, C

Explanation

To meet the requirements, the company should use SSE-KMS with a customer-managed CMK to ensure that their compliance team manages the encryption keys. Additionally, enabling S3 Server Access Logging will provide the necessary access tracking for audit purposes. These solutions together fulfill both the encryption and compliance requirements effectively.

  • A. Incorrect.

    SSE-S3 encrypts data at rest, but the encryption keys are managed by AWS, not the company. This does not meet the requirement for the compliance team to manage the keys.

  • B. Correct.

    SSE-KMS with a customer-managed CMK allows the company to manage their own encryption keys through AWS Key Management Service (KMS), meeting the requirement for internal key management.

  • C. Correct.

    S3 Server Access Logging provides detailed logs about requests made to the bucket, which is essential for auditing and meeting compliance requirements.

  • D. Incorrect.

    S3 Object Lock is used for data immutability, not for tracking access to the data. It does not fulfill the audit requirement in this scenario.

  • E. Incorrect.

    Client-Side Encryption allows the company to manage encryption keys on-premises, but it complicates the migration process and does not integrate well with the requirement to track access for audit purposes.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam