SAP-C02 exam dumps

SAP-C02 practice question 237 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 237

Select 2

Your company is designing a secure data analytics platform on AWS. Sensitive data is stored in Amazon S3 and must be encrypted at rest and in transit. The platform also uses Amazon RDS for relational data, which must comply with strict regulatory requirements for encryption. Which combination of strategies should you implement to ensure compliance and best practices for encryption?

  1. A

    Enable S3 default encryption with AWS Key Management Service (AWS KMS) managed keys and enforce HTTPS for data transfers.

  2. B

    Use Amazon S3 client-side encryption with customer-provided keys and enforce SFTP for data upload.

  3. C

    Enable Transparent Data Encryption (TDE) for Amazon RDS and enforce SSL/TLS for database connections.

  4. D

    Use Amazon S3 bucket policies to restrict access and rely on default server-side encryption without specifying a key.

  5. E

    Use AWS CloudHSM to manage encryption keys for Amazon S3 and enable AWS Lambda to encrypt objects during upload.

Show answer and explanation

Correct answers: A, C

Explanation

The correct strategies for encrypting data at rest and in transit in this scenario align with AWS best practices and compliance requirements. For S3, using AWS KMS managed keys for default encryption ensures secure and manageable key handling, while enforcing HTTPS secures data in transit. For Amazon RDS, Transparent Data Encryption (TDE) provides encryption at rest, and SSL/TLS secures data in transit. These solutions are scalable, compliant, and reduce operational complexity compared to alternatives like client-side encryption or AWS CloudHSM.

  • A. Correct.

    This option is correct because enabling S3 default encryption with AWS KMS managed keys ensures data at rest is encrypted using a secure and scalable solution. Enforcing HTTPS guarantees encryption in transit when accessing objects in S3.

  • B. Incorrect.

    This option is incorrect because while client-side encryption with customer-provided keys is a valid approach, it adds operational complexity and does not align with the managed services typically preferred in AWS for encryption. Additionally, SFTP is not natively supported by S3 and is not the optimal protocol for secure data transfer to S3.

  • C. Correct.

    This option is correct because Transparent Data Encryption (TDE) for Amazon RDS ensures data at rest in the database is encrypted, and enforcing SSL/TLS ensures encryption for data in transit between the application and the database.

  • D. Incorrect.

    This option is incorrect because while S3 bucket policies are important for access control, relying solely on default server-side encryption without specifying a key does not give you control over the encryption method or key management, which may not meet compliance requirements.

  • E. Incorrect.

    This option is incorrect because while AWS CloudHSM can be used for key management, it is generally more complex to manage and not necessary for most use cases with S3. AWS KMS is a more straightforward option for encryption. Additionally, AWS Lambda is not required to encrypt objects during upload since S3 can handle server-side encryption directly.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam