A developer is building a highly secure healthcare application using serverless components. This application requires writing temporary data to /tmp storage on an AWS Lambda function. How should the developer encrypt this data?
A) Enable Amazon EBS volume encryption with an AWS KMS CMK in the Lambda function configuration so that all storage attached to the Lambda function is encrypted.
B) Set up the Lambda function with a role and key policy to access an AWS KMS CMK. Use the CMK to generate a data key used to encrypt all data prior to writing to /tmp storage.
C) Use OpenSSL to generate a symmetric encryption key on Lambda startup. Use this key to encrypt the data prior to writing to /tmp storage.
D) Use an on-premises hardware security module (HSM) to generate keys, where the Lambda function requests a data key from the HSM and uses that to encrypt data on all requests to the function.
Correct Answer:
Verified
Q445: A developer has created a Node.js web
Q446: A developer has designed a customer-facing application
Q447: A company is planning to deploy an
Q448: A developer is storing JSON files in
Q449: A Developer is developing an application that
Q451: A developer is creating a website that
Q452: A developer is building a website that
Q453: A developer is creating a serverless web
Q454: A company wants to make sure that
Q455: An AWS Lambda function accesses two Amazon
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents