Q: 12
A company has an application that uses AWS Key Management Service (AWS KMS) to encrypt and
decrypt dat
a. The application stores data in an Amazon S3 bucket in an AWS Region. Company security policies
require that the data is encryptedbeforebeing uploaded to S3, and decryptedwhen read. The S3
bucket isreplicated to other AWS Regions.
A solutions architect must design a solution so that the application canencrypt and decrypt data
across Regionsusingthe same key.
Options:
Options
Discussion
D . Only multi-Region KMS keys (option A) let you encrypt in one region and decrypt in another using the same logical key. The other options don’t meet that cross-region requirement. If someone knows a better workaround, let me know.
Option A (saw similar on exam reports)
Be respectful. No spam.
Question 12 of 35