A company is preparing to store confidential data in Amazon S3. For compliance reasons, the data must be encrypted at rest. Encryption key usage must be logged for auditing purposes. Keys must be rotated every year. Which solution meets these requirements and is the MOST operationally efficient?
A) Server-side encryption with customer-provided keys (SSE-C)
B) Server-side encryption with Amazon S3 managed keys (SSE-S3)
C) Server-side encryption with AWS KMS (SSE-KMS) customer master keys (CMKs) with manual rotation
D) Server-side encryption with AWS KMS (SSE-KMS) customer master keys (CMKs) with automatic rotation
Correct Answer:
Verified
Q238: An ecommerce website is deploying its web
Q239: A company has an API-based inventory reporting
Q240: A company is preparing to deploy a
Q241: A solutions architect is developing a multiple-subnet
Q242: A disaster response team is using drones
Q244: A company has a mobile game that
Q245: A company is storing sensitive user information
Q246: A company has a multi-tier application deployed
Q247: A company hosts multiple production applications. One
Q248: A company is preparing to migrate its
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents