Q: 17
A company is running a highly sensitive application on Amazon EC2 backed by an Amazon RDS database Compliance regulations mandate that all personally identifiable information (Pll) be encrypted at rest. Which solution should a solutions architect recommend to meet this requirement with the LEAST amount of changes to the infrastructure?
Options
Discussion
Had something like this in a mock, on an exam, pick D.
I get why D looks right, but I keep thinking if compliance ever needs customer-managed keys, then C or B could come up. Still, for most AWS defaults and minimal changes, D is probably safe. Anyone else unsure because of the "highly sensitive" part?
D , I've seen similar questions in practice exams and D lines up with AWS best practice for encrypting both EC2 (EBS) and RDS at rest using KMS. Minimal changes needed here.
D , EBS and RDS encryption with KMS can be enabled with just config changes. Doesn't need big infra mods compared to CloudHSM or ACM stuff. Pretty sure that's the smoothest for least disruption. Agree?
You want encryption at rest for both EC2 and RDS, so D is the fastest way. Just enable EBS and RDS encryption with KMS keys, super minimal changes to setup. Some of the other options need way more integration work, pretty sure D is right.
A is wrong, D. KMS with EBS and RDS encryption is just one config each, super straightforward.
D, Official AWS study guide and practice exams both highlight KMS with EBS and RDS encryption for compliance, fits requirements exactly.
Be respectful. No spam.