SAP-C02 · Question #378
A company consists of two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents
Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #378. The question stem and answer options stay visible for context.
Question
A company consists of two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured two-way replication between the S3 buckets. The S3 buckets have millions of objects. Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3). What is the MOST operationally efficient solution that meets these requirements?
Options
- ATurn on SSE-S3 on both S3 buckets. Use S3 Batch Operations to copy and encrypt the objects in
- BCreate an AWS Key Management Service (AWS KMS) key in each account. Turn on server-side
- CTurn on SSE-S3 on both S3 buckets. Encrypt the existing objects by using an S3 copy command
- DCreate an AWS Key Management Service (AWS KMS) key in each account. Turn on server-side
Unlock SAP-C02 to see the answer
You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.