Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 40 Topic 5 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 40 Topic 5 Discussion

SAA-C03 Exam Topic 5 Question 40 Discussion:
Question #: 40
Topic #: 5

A company runs an environment where data is stored in an Amazon S3 bucket. The objects are accessed frequently throughout the day. The company has strict data encryption requirements fordata that is stored in the S3 bucket. The company currently uses AWS Key Management Service (AWS KMS) for encryption.

The company wants to optimize costs associated with encrypting S3 objects without making additional calls to AWS KMS.

Which solution will meet these requirements?


A.

Use server-side encryption with Amazon S3 managed keys (SSE-S3).


B.

Use an S3 Bucket Key for server-side encryption with AWS KMS keys (SSE-KMS) on the new objects.


C.

Use client-side encryption with AWS KMS customer managed keys.


D.

Use server-side encryption with customer-provided keys (SSE-C) stored in AWS KMS.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.