Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C02 Exam - Topic 2 Question 62 Discussion

[Infrastructure Security]A company uses a third-party application to store encrypted data in Amazon S3. The company uses another third-party application trial decrypts the data from Amazon S3 to ensure separation of duties Between the applications A Security Engineer warns to separate the permissions using IAM roles attached to Amazon EC2 instances. The company prefers to use native IAM services.Which encryption method will meet these requirements?
C) Use server-side encryption with IAM KMS managed keys (SSE-KMS)
A) Use encrypted Amazon EBS volumes with Amazon default keys (IAM EBS)
B) Use server-side encryption with customer-provided keys (SSE-C)
D) Use server-side encryption with Amazon S3 managed keys (SSE-S3)

Amazon SCS-C02 Exam - Topic 2 Question 62 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 62
Topic #: 2
[All SCS-C02 Questions]

[Infrastructure Security]

A company uses a third-party application to store encrypted data in Amazon S3. The company uses another third-party application trial decrypts the data from Amazon S3 to ensure separation of duties Between the applications A Security Engineer warns to separate the permissions using IAM roles attached to Amazon EC2 instances. The company prefers to use native IAM services.

Which encryption method will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Talia
2 days ago
Wait, can you really trust third-party apps for decryption?
upvoted 0 times
...
Theodora
7 days ago
Totally agree, SSE-KMS offers better control!
upvoted 0 times
...
Tamesha
12 days ago
I think C is the best choice with IAM KMS keys.
upvoted 0 times
...
Joaquin
17 days ago
If I remember correctly, using SSE-S3 is the simplest option, but it might not meet the separation of duties requirement as effectively as SSE-KMS.
upvoted 0 times
...
Jessenia
22 days ago
I’m a bit confused about the differences between SSE-KMS and SSE-C. I know one uses customer keys, but I can't recall the implications for permissions.
upvoted 0 times
...
Jamal
28 days ago
I think I came across a similar question about S3 encryption methods in practice exams. I feel like SSE-KMS might be the right choice since it integrates well with IAM.
upvoted 0 times
...
Jovita
1 month ago
I remember studying about IAM roles and how they can help manage permissions, but I'm not entirely sure which encryption method aligns best with that.
upvoted 0 times
...

Save Cancel