SAP-C02 exam dumps

SAP-C02 practice question 446 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 446

Select 3

A company is migrating its on-premises data analytics platform to AWS. The platform processes sensitive customer data, and the company must comply with strict regulatory requirements, including encryption of data at rest and in transit. The company wants to minimize the operational overhead of managing encryption keys while ensuring full control over them. Which combination of AWS services and features should the company use to meet these requirements?

  1. A

    Use AWS Key Management Service (KMS) with customer-managed keys (CMKs) to encrypt data at rest.

  2. B

    Enable AWS CloudHSM to store and manage encryption keys for full control.

  3. C

    Use Amazon S3 with default encryption enabled and AWS-managed keys.

  4. D

    Configure AWS Certificate Manager (ACM) to manage SSL/TLS certificates for encrypting data in transit.

  5. E

    Use AWS Secrets Manager to store and retrieve encryption keys for the platform.

Show answer and explanation

Correct answers: A, B, D

Explanation

The company requires encryption of data both at rest and in transit, with full control over encryption keys to meet regulatory requirements. AWS KMS with customer-managed keys and AWS CloudHSM address the need for controlling encryption keys while minimizing operational overhead. ACM ensures secure encryption of data in transit. Using S3 with AWS-managed keys or Secrets Manager does not meet the requirement for full control over encryption keys.

  • A. Correct.

    Correct: AWS KMS with customer-managed keys (CMKs) allows the company to encrypt data at rest while maintaining full control over the encryption keys. This meets the requirement for regulatory compliance and minimal operational overhead.

  • B. Correct.

    Correct: AWS CloudHSM provides dedicated hardware security modules, allowing the company to manage encryption keys with full control. This is ideal for compliance with strict regulatory requirements.

  • C. Incorrect.

    Incorrect: While Amazon S3 with default encryption and AWS-managed keys offers encryption at rest, it does not provide the company full control over the keys, which is a requirement in this scenario.

  • D. Correct.

    Correct: AWS Certificate Manager (ACM) simplifies the management of SSL/TLS certificates to encrypt data in transit, ensuring compliance with regulatory requirements for secure data transmission.

  • E. Incorrect.

    Incorrect: AWS Secrets Manager is used for managing secrets such as database credentials, API keys, or passwords, but it is not suitable for managing encryption keys for this specific use case.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam