Hard1 markMultiple Choice
Domain 1.2: Security ControlsMigrationSnowballKMSCloudHSM

AWS SAP-C02 · Question 12 · Domain 1.2: Security Controls

An enterprise is migrating its on-premises data lake to Amazon S3. They have 5 PB of data. The data must be encrypted at rest using keys managed by the enterprise's on-premises Hardware Security Module (HSM). The migration must be completed within 30 days, and their internet connection is 1 Gbps, heavily utilized by other workloads. Which combination of steps should the architect take? (Select THREE)

Answer options:

A.

Use AWS DataSync over the existing internet connection.

B.

Order multiple AWS Snowball Edge Storage Optimized devices.

C.

Use AWS KMS with imported key material from the on-premises HSM.

D.

Configure AWS KMS to use a Custom Key Store backed by AWS CloudHSM.

E.

Establish a Site-to-Site VPN to synchronize the on-premises HSM with AWS CloudHSM.

F.

Use AWS Storage Gateway Volume Gateway.

G.

Order an AWS Snowmobile.

How to approach this question

Calculate transfer time (5PB over 1Gbps = too slow -> Snowball). Identify KMS Custom Key Store for HSM integration.

Full Answer

Transferring 5 PB over a 1 Gbps link would take over a year, so AWS Snowball Edge is required. To use keys managed by an HSM, AWS KMS Custom Key Store backed by AWS CloudHSM is used, which can be synchronized with the on-premises HSM over a VPN/DX.

Common mistakes

Selecting DataSync without doing the math on transfer time.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 4

75 questions · hints · full answers · grading

More questions from this exam