SOA-C02 · Question #172
A company is partnering with an external vendor to provide data processing services. For this integration, the vendor must host the company's data in an Amazon S3 bucket in the vendor's AWS account…
The correct answer is A. Create a new KMS key. The vendor is required to host the S3 bucket. It holds the company's data. The vendor wants to use a company-provided key to encrypt the data. So the company needs to create the new key and then provide access to that key from the IAM role which was provided by the vendor.
Question
A company is partnering with an external vendor to provide data processing services. For this integration, the vendor must host the company’s data in an Amazon S3 bucket in the vendor’s AWS account. The vendor is allowing the company to provide an AWS Key Management Service (AWS KMS) key to encrypt the company’s data. The vendor has provided an IAM role Amazon Resources Name (ARN) to the company for this integration. What should a SysOps administrator do to configure this integration?
Options
- ACreate a new KMS key.
- BCreate a new KMS key.
- CConfigure encryption using the KMS managed S3 key.
- DConfigure encryption using the KMS managed S3 key.
How the community answered
(45 responses)- A76% (34)
- B2% (1)
- C13% (6)
- D9% (4)
Explanation
The vendor is required to host the S3 bucket. It holds the company's data. The vendor wants to use a company-provided key to encrypt the data. So the company needs to create the new key and then provide access to that key from the IAM role which was provided by the vendor.
Topics
Community Discussion
No community discussion yet for this question.