A company is running a highly sensitive application on Amazon EC2 backed by an Amazon RDS database. Compliance regulations mandate that all personally identifiable information (PII) be encrypted at rest. Which solution should a solutions architect recommend to meet this requirement with the LEAST amount of changes to the infrastructure?
A) Deploy AWS Certificate Manager to generate certificates. Use the certificates to encrypt the database volume.
B) Deploy AWS CloudHSM, generate encryption keys, and use the customer master key (CMK) to encrypt database volumes.
C) Configure SSL encryption using AWS Key Management Service customer master keys (AWS KMS CMKs) to encrypt database volumes.
D) Configure Amazon Elastic Block Store (Amazon EBS) encryption and Amazon RDS encryption with AWS Key Management Service (AWS KMS) keys to encrypt instance and database volumes.
Correct Answer:
Verified
Q75: A solutions architect is moving the static
Q76: A media company is evaluating the possibility
Q77: An ecommerce company is running a multi-tier
Q78: A company's application hosted on Amazon EC2
Q79: A company plans to store sensitive user
Q81: A company needs to implement a relational
Q82: A company is planning to build a
Q83: A solutions architect must migrate a Windows
Q84: A company is planning to migrate its
Q85: A company runs a web service on
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents