AWS Certified Developer Associate DVA-C02 Practice Question
A developer is designing a new application that processes sensitive financial data. The application will store processed data in Amazon S3. For compliance reasons, the data must be encrypted at all times. Which type of encryption should the developer use to ensure that the data is encrypted before it leaves the application's host and remains encrypted in transit and at rest within Amazon S3?
You selected this option
Use server-side encryption with Amazon S3 managed keys (SSE-S3) when uploading the data.
You selected this option
Enable Secure Socket Layer (SSL) on the application's server and rely on S3 bucket policies to handle encryption.
You selected this option
Implement client-side encryption using a customer-managed key prior to uploading the data to Amazon S3.
You selected this option
Activate default S3 bucket encryption with an AWS Key Management Service (KMS) managed key.
Server-side encryption with Amazon S3 managed keys (SSE-S3) will encrypt the data as it arrives in S3, but does not guarantee that data is encrypted in transit or before it leaves the application's host. Using client-side encryption, the data is encrypted by the client (in this case, the application), which ensures that data is encrypted before it is sent over the network to Amazon S3. As a result, the data remains encrypted in transit and when stored at rest in S3. Other options are incorrect because they either involve encryption managed by S3 after the data has been uploaded (missing in transit encryption), or are not related to S3.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is client-side encryption and how does it work?
Open an interactive chat with Bash
What are the differences between client-side encryption and server-side encryption?
Open an interactive chat with Bash
What are AWS Key Management Service (KMS) managed keys and how are they used?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Oh snap!
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access