AWS Certified Developer Associate DVA-C02 Practice Question
A development team must secure sensitive customer files in cloud-based object storage. The requirements stipulate that the encryption keys used should be under the company's direct control, with an automated process for changing these keys periodically. Which service and configuration would best fulfill these criteria?
You selected this option
Adopt a hardware security module service for key storage and institute a manual rotation process
You selected this option
Engage a private certificate authority to apply server-side encryption policies to the cloud storage
You selected this option
Use self-managed keys in Key Management Service set to automatically rotate for object storage server-side encryption
You selected this option
Enable a managed key rotation service within the platform's cloud object storage
The appropriate service for the creation and administration of encryption keys in the cloud is Key Management Service (KMS), which provides options to both create your own encryption keys and configure them for automatic rotation. Utilizing KMS keys offers the capability to fulfill the need for encryption at rest within S3 while also adhering to the company's guidelines for regular key rotation. The reliance on the platform's own managed keys would preclude direct control and rotation management. Certificate Manager's primary use case involves issuing certificates for TLS, not storage encryption, while CloudHSM is tailored for specific compliance requirements and does not innately manage automatic key rotation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Key Management Service (KMS) in AWS?
Open an interactive chat with Bash
How does automated key rotation work in AWS KMS?
Open an interactive chat with Bash
Why is self-managed key rotation preferable for sensitive data?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Oh snap!
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access