Hard1 markMultiple Choice
Domain 1.3: Data SecurityCloudHSMEncryptionCompliance

AWS SAA-C03 · Question 19 · Domain 1.3: Data Security

A government agency is migrating to AWS. They require dedicated hardware for cryptographic key generation and storage to meet FIPS 140-2 Level 3 compliance. They must have exclusive control over the cryptographic keys.<br/><br/>Which TWO statements about the appropriate AWS service are correct? (Select TWO.)

Answer options:

A.

The agency should use AWS KMS.

B.

The agency should use AWS CloudHSM.

C.

AWS manages the key rotation automatically.

D.

AWS does not have access to the keys stored in the service.

E.

The service is serverless and scales automatically per request.

How to approach this question

Identify the service that provides dedicated hardware and single-tenant key control.

Full Answer

AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud. It provides exclusive, single-tenant control over keys and meets FIPS 140-2 Level 3 compliance. AWS has no access to your keys.

Common mistakes

Confusing KMS (managed, multi-tenant) with CloudHSM (dedicated, single-tenant).

Practice the full AWS SAA-C03 Practice Exam 6

65 questions · hints · full answers · grading

More questions from this exam