Medium1 markMultiple Choice
Domain 1.3: Data SecurityDomain 1SecurityKMSS3

AWS SAA-C03 · Question 03 · Domain 1.3: Data Security

A company is storing highly sensitive data in an Amazon S3 bucket. The security team requires that the data is encrypted at rest using keys managed by the company, and that all API calls to the keys are logged. Which TWO actions should a solutions architect take? (Select TWO.)

Answer options:

A.

Use Amazon S3 managed keys (SSE-S3).

B.

Use AWS KMS Customer Managed Keys (CMKs).

C.

Enable AWS CloudTrail to log KMS API calls.

D.

Use AWS Secrets Manager to store the encryption keys.

E.

Enable Amazon Macie to log key usage.

How to approach this question

Identify the key management service and logging service.

Full Answer

AWS KMS CMKs provide customer control over encryption keys. CloudTrail logs all API requests to KMS.

Common mistakes

Selecting SSE-S3 which doesn't provide customer control over the keys.

Practice the full AWS SAA-C03 Practice Exam 2

65 questions · hints · full answers · grading

More questions from this exam