Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Solutions Architect - Professional SAP-C02 Question # 99 Topic 10 Discussion

Amazon Web Services AWS Certified Solutions Architect - Professional SAP-C02 Question # 99 Topic 10 Discussion

SAP-C02 Exam Topic 10 Question 99 Discussion:
Question #: 99
Topic #: 10

Question:

A company has an application that uses AWS Key Management Service (AWS KMS) to encrypt and decrypt data. The application stores data in an Amazon S3 bucket in an AWS Region. Company security policies require that the data is encryptedbeforebeing uploaded to S3, and decryptedwhen read. The S3 bucket isreplicated to other AWS Regions.

A solutions architect must design a solution so that the application canencrypt and decrypt data across Regionsusingthe same key.

Options:


A.

Create a KMS multi-Region primary key. Use it to create KMS multi-Region replica keys in each Region. Update application code to use the replica key in each Region.


B.

Create a new customer-managed KMS key in each additional Region. Update application code to use the key in each Region.


C.

Use AWS Private CA to issue TLS certificates and replicate them with AWS RAM.


D.

Export the KMS key material to Systems Manager Parameter Store in each Region. Update the app to use those.


Get Premium SAP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.