SCS-C02 · Question #213
A security engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highly scalable without requiring
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #213. The question stem and answer options stay visible for context.
Question
A security engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highly scalable without requiring continual management. Additionally, the organization must be able to immediately delete the encryption keys. Which solution meets these requirements?
Options
- AUse AWS KMS with AWS managed keys and the ScheduleKeyDeletion API with a
- BUse KMS with AWS imported key material and then use the DeletelmportedKeyMaterial API to
- CUse AWS CloudHSM to store the keys and then use the CloudHSM API or the PKCS11 library to
- DUse the Systems Manager Parameter Store to store the keys and then use the service API
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.