Soru

Zorluk: KolayData Protection and Encryption

A retail company wants to store its weekly sales reports in Amazon Simple Storage Service (Amazon S3). To protect this data, they want to enable encryption at rest using cryptographic keys that are fully managed by AWS. Which AWS service is designed to easily create and manage these encryption keys?

  1. AWS Key Management Service (AWS KMS)Cevap
  2. B
    AWS CloudHSM
  3. C
    AWS CloudTrail
  4. D
    AWS Artifact

Cevap

AWS Key Management Service (AWS KMS)
AWS Key Management Service (AWS KMS) is a fully managed service that integrates with many AWS services (such as Amazon S3) to easily create, manage, and rotate cryptographic keys used to secure data at rest.

Adım Adım Çözüm

1
Identify the core requirement from the scenario.
The requirement is to encrypt data at rest in Amazon S3 using a fully managed key management service.
This narrows down the choice to services that deal with encryption and key management.
2
Evaluate the managed services offered by AWS for cryptographic key management.
AWS Key Management Service (AWS KMS) is the standard multi-tenant managed service for creating and managing keys. AWS CloudHSM offers dedicated hardware security modules but requires manual management by the customer.
Since the scenario specifies a fully managed service that easily creates and manages keys, AWS KMS is the correct fit.

Anahtar Kavram

AWS Key Management Service (AWS KMS) provides a fully managed, secure solution for creating and controlling cryptographic keys to encrypt data at rest across AWS services.
Tahmini Süre:45s
Bu soruyu puanla