Security & ComplianceQuestion 50 of 100
A customer stores objects in Amazon S3 and wants AWS to manage the encryption keys and apply encryption automatically. Which option fits?
a.Disable encryption entirely
b.Store keys in the application source code
c.Server-side encryption with keys managed by AWS (SSE)
d.Only encrypt data after downloading it locally
Explanation
Server-side encryption lets AWS encrypt object data at rest, with key management handled by S3 or KMS. This provides encryption at rest without the customer having to build their own encryption process.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which AWS service can be used to provision and manage SSL/TLS certificates for use with AWS services like load balancers and CloudFront?
- Which of the following is an IAM best practice?
- Which service aggregates security findings from services like GuardDuty, Inspector, and Macie into a single dashboard and runs automated best-practice checks?
- Which statement best distinguishes an IAM user from an IAM role?
- According to the shared responsibility model, who is responsible for classifying data and configuring access controls on it?
- Which service would you use to get automated recommendations that include security checks such as identifying publicly accessible resources or missing MFA on the root account?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against AWS Certified Cloud Practitioner (CLF-C02) · How we review