Certified Solutions Architect Data Encryption with KMS Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Certified Solutions Architect Data Encryption with KMS flashcards as text
A company needs to encrypt SQS messages using KMS. After enabling SSE on the SQS queue, a Lambda function fails to process messages with an access denied error. What is the most likely cause?
Answer: The Lambda execution role lacks kms:Decrypt permission on the KMS key used by SQS
When SQS is encrypted with KMS, consumers like Lambda need kms:Decrypt (and kms:GenerateDataKey) permissions on the key to receive and process messages.
What is the purpose of the kms:ViaService condition key in a KMS key policy?
Answer: It allows or denies KMS key usage only when the request comes through a specified AWS service
The kms:ViaService condition key restricts KMS key usage so it can only be invoked through a specified AWS service (e.g., s3.us-east-1.amazonaws.com), preventing direct API usage.
An architect is designing a multi-tenant SaaS application on AWS where each tenant's data must be encrypted with a separate KMS key. What is a key operational concern with this approach?
Answer: Each additional CMK increases cost and the number of API calls, which may hit KMS request quotas
Using one CMK per tenant increases monthly key costs and KMS API request volume, which can exhaust service quotas — architects must plan for quota increases and cost implications.
A solutions architect needs to re-encrypt data in S3 that was encrypted with KMS key A using KMS key B, without downloading the data. Which KMS API supports this operation?
Answer: kms:ReEncrypt
The kms:ReEncrypt API allows ciphertext encrypted under one KMS key to be re-encrypted under a different KMS key entirely within KMS, without exposing the plaintext.
Which statement correctly describes the behavior of KMS key aliases?
Answer: An alias is a friendly name that points to a KMS key and can be reassigned to a different key
A KMS alias is a display name that maps to a KMS key ARN; it can be updated to point to a different key, enabling key rotation in applications without code changes.
A CloudFormation template creates an encrypted EBS volume. The template developer wants the volume to use the default AWS managed key for EBS. Which KMS key alias should be referenced?
Answer: alias/aws/ebs
The AWS managed key for EBS is accessible via the alias alias/aws/ebs, which is the default key used when no customer managed key is specified for EBS encryption.
A company is using AWS KMS with CloudHSM key store (custom key store) instead of the default KMS key store. What is the primary reason for this architecture choice?
Answer: To maintain exclusive control of the HSM and ensure key material never leaves the HSM
A CloudHSM custom key store keeps key material in customer-managed HSM clusters so the cryptographic operations occur within the HSM, giving customers exclusive control and ensuring key material never leaves their HSM.