Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 38 Topic 4 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 38 Topic 4 Discussion

SCS-C03 Exam Topic 4 Question 38 Discussion:
Question #: 38
Topic #: 4

A company has a PHP-based web application that uses Amazon S3 as an object store for user files. The S3 bucket is configured for server-side encryption with Amazon S3 managed keys (SSE-S3). New requirements mandate full control of encryption keys.

Which combination of steps must a security engineer take to meet these requirements? (Select THREE.)


A.

Create a new customer managed key in AWS Key Management Service (AWS KMS).


B.

Change the SSE-S3 configuration on the S3 bucket to server-side encryption with customer-provided keys (SSE-C).


C.

Configure the PHP SDK to use the SSE-S3 key before upload.


D.

Create an AWS managed key for Amazon S3 in AWS KMS.


E.

Change the SSE-S3 configuration on the S3 bucket to server-side encryption with AWS KMS managed keys (SSE-KMS).


F.

Change all the S3 objects in the bucket to use the new encryption key.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.