SCS-C02 · Question #414
A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers. The ap
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #414. The question stem and answer options stay visible for context.
Question
A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers. The application will send the credit card numbers to a component that is running in an isolated environment. The component will encrypt, store, and decrypt the numbers. The component then will issue tokens to replace the numbers in other parts of the application. The component of the application that manages the tokenization process will be deployed on a separate set of EC2 instances. Other components of the application must not be able to store or access the credit card numbers. Which solution will meet these requirements?
Options
- AUse EC2 Dedicated Instances for the tokenization component of the application.
- BPlace the EC2 instances that manage the tokenization process into a partition placement group.
- CCreate a separate VPC. Deploy new EC2 instances into the separate VPC to support the data
- DDeploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances.
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.