Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 31 Topic 4 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 31 Topic 4 Discussion

SAA-C03 Exam Topic 4 Question 31 Discussion:
Question #: 31
Topic #: 4

A company hosts an application that processes highly sensitive customer transactions on AWS. The application uses Amazon RDS as its database. The company manages its own encryption keys to secure the data in Amazon RDS.

The company needs to update the customer-managed encryption keys at least once each year.

Which solution will meet these requirements with the LEAST operational overhead?


A.

Set up automatic key rotation in AWS Key Management Service (AWS KMS) for the encryption keys.


B.

Configure AWS Key Management Service (AWS KMS) to alert the company to rotate the encryption keys annually.


C.

Schedule an AWS Lambda function to rotate the encryption keys annually.


D.

Create an AWS CloudFormation stack to run an AWS Lambda function that deploys new encryption keys once each year.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.