Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SAA-C03 Exam - Topic 4 Question 71 Discussion

A company needs to store confidential files on AWS. The company accesses the files every week. The company must encrypt the files by using envelope encryption, and the encryption keys must be rotated automatically. The company must have an audit trail to monitor encryption key usage.Which combination of solutions will meet these requirements? (Select TWO.)
A) Store the confidential files in Amazon S3. and E) Use server-side encryption with AWS KMS managed keys (SSE-KMS).
B) Store the confidential files in Amazon S3 Glacier Deep Archive.
C) Use server-side encryption with customer-provided keys (SSE-C).
D) Use server-side encryption with Amazon S3 managed keys (SSE-S3).

Amazon SAA-C03 Exam - Topic 4 Question 71 Discussion

Actual exam question for Amazon's SAA-C03 exam
Question #: 71
Topic #: 4
[All SAA-C03 Questions]

A company needs to store confidential files on AWS. The company accesses the files every week. The company must encrypt the files by using envelope encryption, and the encryption keys must be rotated automatically. The company must have an audit trail to monitor encryption key usage.

Which combination of solutions will meet these requirements? (Select TWO.)

Show Suggested Answer Hide Answer
Suggested Answer: A, E

Amazon S3 is suitable for storing data that needs to be accessed weekly and integrates with AWS Key Management Service (KMS) to provide encryption at rest with server-side encryption using KMS-managed keys (SSE-KMS).

SSE-KMS uses envelope encryption and allows automatic key rotation and logging through AWS CloudTrail, satisfying the requirements for audit trails and compliance.

S3 Glacier Deep Archive is unsuitable due to its high retrieval latency. SSE-C requires customer-side management of encryption keys, with no support for automatic rotation or audit. SSE-S3 does not use customer-managed keys and lacks fine-grained control and auditing.


Contribute your Thoughts:

0/2000 characters
Desmond
8 days ago
I’m not sure about A. What if we need long-term storage? B could be better.
upvoted 0 times
...
Freeman
13 days ago
Agreed! E ensures automatic key rotation and audit trails.
upvoted 0 times
...
Jovita
18 days ago
I think A and E are the best choices. S3 is perfect for storage.
upvoted 0 times
...
Fatima
23 days ago
SSE-KMS is the way to go for audit trails!
upvoted 0 times
...
Domingo
29 days ago
Wait, can you really automate key rotation with SSE-S3?
upvoted 0 times
...
Cecily
1 month ago
I agree, A and E seem to fit perfectly!
upvoted 0 times
...
Lorrie
3 months ago
I think B is a bad choice here, too slow for weekly access.
upvoted 0 times
...
Bettina
3 months ago
Definitely A and E for this scenario.
upvoted 0 times
...
Florinda
4 months ago
I feel like SSE-S3 is simpler but might not provide the audit trail we need. I’m leaning towards SSE-KMS for that reason.
upvoted 0 times
...
Naomi
4 months ago
I practiced a similar question where SSE-KMS was the right choice for automatic key rotation. I think it’s definitely one of the answers here.
upvoted 0 times
...
Wayne
4 months ago
I’m a bit unsure about the storage options. I know S3 is good for frequent access, but does Glacier Deep Archive meet the access requirement?
upvoted 0 times
...
In
4 months ago
I remember that envelope encryption involves using a data key to encrypt the files and then encrypting that data key with a master key. I think AWS KMS is the way to go for managing those keys.
upvoted 0 times
...

Save Cancel