Labor Day Flash Sale: 30% off Today Only!

1 hour, 14 minutes remaining!

AWS Certified Solutions Architect Associate SAA-C03 Practice Question

A security engineer must protect sensitive data that is uploaded to an Amazon S3 bucket. The engineer's requirements are:

  • Encrypt data in transit by allowing only SSL/TLS connections to the bucket.
  • Encrypt data at rest with the customer-managed AWS KMS key arn:aws:kms:us-east-1:123456789012:key/abcd1234.

Which of the following statements best describes AWS best practice for meeting both requirements?

  • A bucket policy can enforce SSL/TLS, but it can require only the AWS-managed key (aws/s3); customer-managed keys cannot be specified in policy conditions.

  • Enforcing SSL/TLS and a specific customer-managed KMS key in the bucket policy aligns with AWS security best practices for protecting data in transit and at rest.

  • Using a bucket policy to require SSL/TLS is unnecessary because Amazon S3 automatically forces HTTPS; only default encryption needs to be enabled.

  • Enabling SSE-S3 encryption at rest makes enforcing SSL/TLS in transit redundant, so the bucket policy only needs to specify the aes256 header.

AWS Certified Solutions Architect Associate SAA-C03
Design Secure Architectures
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot