SAP-C02 exam dumps

SAP-C02 practice question 65 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 65

Select 2

A financial services company uses an application that requires secure communication between its web servers and customers' browsers. The company also needs to ensure that encryption keys used for securing data at rest are rotated automatically and comply with regulatory requirements. Which combination of AWS services should the company use to meet these needs?

  1. A

    Use AWS Certificate Manager (ACM) to provision and manage SSL/TLS certificates for secure communication between web servers and browsers.

  2. B

    Use AWS Key Management Service (KMS) to manage encryption keys for data at rest and automate key rotation.

  3. C

    Manually generate SSL/TLS certificates and store them in Amazon S3 for secure access.

  4. D

    Use Amazon Elastic Block Store (EBS) default encryption without integrating with AWS Key Management Service (KMS).

  5. E

    Deploy AWS CloudHSM to manage SSL/TLS certificates and encryption keys entirely on-premises.

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirements of secure communication and regulatory compliance, the company should use AWS Certificate Manager (ACM) for SSL/TLS certificate management and AWS Key Management Service (KMS) for managing encryption keys and automating key rotation. These services are designed to simplify security management in cloud environments, ensuring compliance and efficient operations.

  • A. Correct.

    This is correct. AWS Certificate Manager (ACM) simplifies the provisioning, management, and deployment of SSL/TLS certificates, ensuring secure communication between web servers and browsers.

  • B. Correct.

    This is correct. AWS Key Management Service (KMS) provides centralized control over encryption keys, automates key rotation, and complies with regulatory requirements.

  • C. Incorrect.

    This is incorrect. Manually generating and managing SSL/TLS certificates is error-prone, lacks automation, and does not leverage ACM's capabilities for secure and efficient certificate management.

  • D. Incorrect.

    This is incorrect. While EBS default encryption provides encryption at rest, it does not address the need for centralized key management or automated key rotation using KMS.

  • E. Incorrect.

    This is incorrect. AWS CloudHSM is a hardware security module for specific use cases that require dedicated hardware for key management. It is not meant for managing SSL/TLS certificates, and it introduces unnecessary complexity for this scenario.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam