← All AWS Flashcard Decks

Certified Solutions Architect Data Encryption with KMS Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Certified Solutions Architect Data Encryption with KMS flashcards as text
  1. An application on EC2 must encrypt data before writing it to S3 and decrypt it on read, without relying on S3 server-side encryption. Which approach implements client-side encryption with KMS?

    Answer: Use the AWS Encryption SDK with a KMS keyring to encrypt data before calling PutObject

    The AWS Encryption SDK integrates with KMS via keyrings, allowing applications to encrypt data locally before sending it to S3, ensuring encryption happens entirely on the client side.

  2. A KMS customer managed key has automatic key rotation enabled. After rotation, data encrypted with the previous key version is decrypted using which key version?

    Answer: The specific key version that was active when the data was encrypted

    KMS retains all previous key versions and automatically uses the correct version to decrypt ciphertext, based on metadata embedded in the encrypted data.

  3. Which of the following statements about KMS grants is TRUE?

    Answer: Grants allow temporary, delegated permissions on a KMS key and can be retired by the grantee or issuer

    KMS grants are a mechanism for temporary access delegation, allowing a principal to use a key for specific operations, and they can be retired when no longer needed.

  4. A solutions architect must encrypt data in DynamoDB at rest using a customer managed KMS key. How is encryption configured for DynamoDB?

    Answer: Enable encryption in the DynamoDB table settings and select the customer managed KMS key

    DynamoDB supports native server-side encryption with a customer managed KMS key, configured during table creation or modification via the AWS Console, CLI, or API.

  5. An architect needs to share a customer managed KMS key with another AWS account so that account can use it to decrypt data. What is the correct method?

    Answer: Add the other account's principal to the key policy and optionally configure IAM permissions in that account

    Cross-account KMS key access requires updating the key policy in the owning account to allow the external account, and then the external account creates IAM policies to grant its users access.

  6. Which AWS service uses KMS envelope encryption to protect secrets at rest by default when a customer managed key is selected?

    Answer: AWS Secrets Manager

    AWS Secrets Manager encrypts secret values using envelope encryption with KMS — it generates a data key from KMS, encrypts the secret value, and stores the encrypted data key alongside the secret.

  7. A company's security policy requires that encryption keys used for S3 data never leave AWS KMS in plaintext form. Which S3 encryption option satisfies this requirement?

    Answer: SSE-KMS (Server-Side Encryption with AWS KMS keys)

    With SSE-KMS, the data encryption key is generated and managed within KMS and never leaves KMS in plaintext; S3 only receives the plaintext key temporarily in memory for encryption.