Ends in
00
days
00
hrs
00
mins
00
secs
SHOP NOW

💝 Valentine's Sale! Get 30% OFF Any Reviewer. Use coupon code: PASSION-4-CLOUD & 10% OFF Store Credits/Gift Cards

Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Security – Specialty Section-Based – Data Protection (Security) Question

  • Section-Based – Data Protection (Security) Question

  • hellojellojw

    Member
    January 26, 2025 at 10:10 am

    <div>Hi, I have an issue with this question:</div>

    A company is looking to store their confidential financial files in AWS that are accessed every week. A Security Engineer was instructed to set up the storage system which uses envelope encryption and automates key rotation. It should also provide an audit trail which shows who used the encryption key and by whom for security purposes.

    Which of the following should the Engineer implement to satisfy the requirement with the LEAST amount of cost? (Select TWO.)

    <div> Enable Server-Side Encryption with Customer-Provided Keys (SSE-C).</div>

    Store the confidential financial files in Amazon S3. – CORRECT

    Store the confidential financial files in Amazon S3 Glacier Deep Archive.

    Enable Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3).

    Enable Server-Side Encryption with AWS KMS Keys (SSE-KMS). – CORRECT

    The option that says: Enable Server-Side Encryption with Customer-Provided Keys (SSE-C) and Enabling Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
    are incorrect. Although you can configure automatic key rotation, these
    two do not provide you with an audit trail that shows when your KMS key
    was used and by whom, unlike Server-Side Encryption with AWS KMS Keys
    (SSE-KMS).

    The explanation is wrong, per AWS you can track SSE-C usage: https://repost.aws/articles/ARhGC12rOiTBCKHcAe9GZXCA/how-to-detect-existing-use-of-sse-c-in-your-amazon-s3-buckets.

    Either the question should be updated or the answers clarified.

  • JR-TutorialsDojo

    Administrator
    January 28, 2025 at 10:39 am

    Hi hellojellojw,

    Thank you for pointing that out.

    We will make the necessary updates, which should be reflected on the portal soon.

    Let us know if you need further assistance.

    Regards,
    JR @ Tutorials Dojo

Viewing 1 - 2 of 2 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now
Skip to content