AWS Certified Solutions Architect Associate SAA-C03 Practice Question
An organization is looking to migrate sensitive financial records to Amazon S3 for storage and regulatory compliance purposes. The Chief Security Officer (CSO) wants to ensure that the data is encrypted at rest using a managed service that allows control over the encryption keys and their rotation. Which service should be used to encrypt the data at rest while allowing the organization full control over the encryption keys and their rotation schedules?
Amazon S3 with AWS Key Management Service (KMS)
Amazon S3 with AWS Certificate Manager (ACM)
Amazon S3 with Amazon Macie
Amazon S3 with AWS CloudHSM