SAP-C02 exam dumps

SAP-C02 practice question 234 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 234

Select 2

A financial services company needs to comply with strict regulatory requirements to secure sensitive customer data both at rest and in transit. They are using Amazon S3 to store customer records and an application hosted on Amazon EC2 instances to transmit sensitive data to third-party APIs over the internet. Which combination of options ensures compliance with the encryption requirements for both data at rest and data in transit?

  1. A

    Enable Amazon S3 Default Encryption using SSE-KMS and configure a customer-managed CMK.

  2. B

    Use AWS Certificate Manager (ACM) to provision a TLS certificate for securing communication between the application and the third-party APIs.

  3. C

    Enable Amazon S3 Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3).

  4. D

    Use AWS CloudHSM to store encryption keys for S3 data and configure the application to use HTTPS for all API calls.

  5. E

    Use Amazon S3 Client-Side Encryption and upload encrypted objects to S3 using the AWS SDK.

Show answer and explanation

Correct answers: A, B

Explanation

To comply with strict regulatory requirements for encryption, the company needs to ensure data at rest in S3 is encrypted using SSE-KMS with a customer-managed CMK, which provides strong encryption and full control over key management. Additionally, securing data in transit requires using TLS, which can be provisioned with AWS Certificate Manager (ACM). These options together address both data at rest and in transit encryption requirements effectively and align with AWS best practices.

  • A. Correct.

    Option 1 is correct because enabling Amazon S3 Default Encryption with SSE-KMS and a customer-managed CMK provides strong encryption for data at rest, meeting compliance requirements. Customer-managed CMKs give the company full control over key management and lifecycle.

  • B. Correct.

    Option 2 is correct because AWS Certificate Manager (ACM) provisions TLS certificates to secure data in transit. This ensures that sensitive data transmitted to third-party APIs is encrypted and meets regulatory standards.

  • C. Incorrect.

    Option 3 is incorrect because while SSE-S3 provides encryption at rest, it does not offer the same level of control over key management as SSE-KMS with a customer-managed CMK, which is a regulatory requirement for sensitive data.

  • D. Incorrect.

    Option 4 is incorrect because AWS CloudHSM is not required in this scenario as SSE-KMS with a customer-managed CMK already meets the encryption at rest requirements. Additionally, AWS CloudHSM is typically used for more specialized use cases like custom cryptographic operations.

  • E. Incorrect.

    Option 5 is incorrect because client-side encryption requires the company to manage encryption keys and processes entirely on their own. While this might meet the compliance requirement, it adds unnecessary complexity compared to using AWS-managed encryption options.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam