SAA-C03 exam dumps

SAA-C03 practice question 87 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 87

Select 2

A company is building a new application that stores sensitive customer data in Amazon S3. The company requires that the data be encrypted both at rest and in transit. Additionally, they want complete control over the encryption keys used for the data. Which combination of solutions will meet these requirements?

  1. A

    Use Amazon S3 default server-side encryption with AES-256 and enable SSL/TLS for data in transit.

  2. B

    Use Amazon S3 server-side encryption with AWS KMS-managed keys (SSE-KMS) and enable SSL/TLS for data in transit.

  3. C

    Use Amazon S3 server-side encryption with customer-provided keys (SSE-C) and enable SSL/TLS for data in transit.

  4. D

    Use client-side encryption with AWS KMS for managing encryption keys and enable SSL/TLS for data in transit.

  5. E

    Use Amazon S3 bucket policies to enforce encryption and disable SSL/TLS for data in transit.

Show answer and explanation

Correct answers: C, D

Explanation

The company requires complete control over encryption keys for data stored in Amazon S3 and encryption for data in transit. Option 3 (SSE-C) allows the company to manage their own encryption keys while AWS handles encryption and decryption. Option 4 (client-side encryption) also meets the requirements by allowing the company to encrypt data using their own keys before uploading it to S3. Both solutions combine with SSL/TLS to secure data in transit, fully meeting the requirements. Other options either do not provide full key control or violate encryption requirements.

  • A. Incorrect.

    This option uses Amazon S3's default encryption (SSE-S3), which does not provide the company with complete control over the encryption keys. While enabling SSL/TLS secures data in transit, this option does not meet the requirement for full key control.

  • B. Incorrect.

    While SSE-KMS provides some control over encryption keys, the company does not have full control since AWS manages the keys within the KMS service. Enabling SSL/TLS secures data in transit, but this option does not fully meet the requirements.

  • C. Correct.

    SSE-C allows the company to provide and manage their own encryption keys, giving them full control over the keys. SSL/TLS ensures that data is encrypted during transit, making this a valid solution for the requirements.

  • D. Correct.

    With client-side encryption, the company encrypts data before uploading it to Amazon S3 and can manage the encryption keys using AWS KMS or their own key management system. Enabling SSL/TLS secures data in transit, fulfilling both requirements.

  • E. Incorrect.

    Disabling SSL/TLS for data in transit directly violates the requirement to encrypt data in transit, making this option invalid regardless of the use of bucket policies.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam