nerdexam
Amazon

SAP-C02 · Question #757

A company has an application that uses AWS Key Management Service (AWS KMS) to encrypt and decrypt data. The application stores data in an Amazon S3 bucket in an AWS Region. Company security policies

Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #757. The question stem and answer options stay visible for context.

Submitted by yuki_2020· Mar 6, 2026Continuous Improvement for Existing Solutions

Question

A company has an application that uses AWS Key Management Service (AWS KMS) to encrypt and decrypt data. The application stores data in an Amazon S3 bucket in an AWS Region. Company security policies require the data to be encrypted before the data is placed into the S3 bucket. The application must decrypt the data when the application reads files from the S3 bucket. The company replicates the S3 bucket to other Regions. A solutions architect must design a solution so that the application can encrypt and decrypt data across Regions. The application must use the same key to decrypt the data in each Region. Which solution will meet these requirements?

Options

  • ACreate a KMS multi-Region primary key. Use the KMS multi-Region primary key to create a KMS
  • BCreate a new customer managed KMS key in each additional Region where the application is
  • CUse AWS Private Certificate Authority to create a new certificate authority (CA) in the primary
  • DUse AWS Systems Manager Parameter Store to create a parameter in each additional Region

Unlock SAP-C02 to see the answer

You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SAP-C02 Practice