AWS SAA-C03 #121

A company is running an online transaction processing (OLTP) workload on AWS. This workload uses an unencrypted Amazon RDS DB instance in a Multi-AZ deployment. Daily database snapshots are taken from this instance.

What should a solutions architect do to ensure the database and snapshots are always encrypted moving forward?

A. Encrypt a copy of the latest DB snapshot. Replace existing DB instance by restoring the encrypted snapshot.

B. Create a new encrypted Amazon Elastic Block Store (Amazon EBS) volume and copy the snapshots to it. Enable encryption on the DB instance.

C. Copy the snapshots and enable encryption using AWS Key Management Service (AWS KMS) Restore encrypted snapshot to an existing DB instance.

D. Copy the snapshots to an Amazon S3 bucket that is encrypted using server-side encryption with AWS Key Management Service (AWS KMS) managed keys (SSE-KMS).


The correct answer is A. Encrypt a copy of the latest DB snapshot. Replace existing DB instance by restoring the encrypted snapshot.

Here's why:

  • Amazon RDS does not support encrypting an existing DB instance. Therefore, to encrypt an existing unencrypted DB instance, you must create a snapshot of the DB instance, and then create a copy of that snapshot that is encrypted. You can then restore a DB instance from the encrypted snapshot, and thus you have an encrypted copy of the original DB instance.

  • Options B, C, and D are not valid because they either involve steps that are not supported by AWS or they do not result in an encrypted DB instance.

Remember, it's important to understand the capabilities and limitations of the AWS services you are using to ensure you are implementing solutions that are secure and efficient. If you have any more questions, feel free to ask!

Sure, here's why the other options are incorrect:

  • Option B: Amazon Elastic Block Store (Amazon EBS) and Amazon RDS are different services with different capabilities. Amazon EBS volumes can be encrypted at any time, but Amazon RDS DB instances cannot be encrypted after they are created. Therefore, copying snapshots to an encrypted EBS volume would not result in an encrypted DB instance.

  • Option C: While you can copy a snapshot and enable encryption using AWS Key Management Service (AWS KMS), you cannot restore an encrypted snapshot to an existing DB instance. The existing DB instance would need to be deleted and a new one created from the encrypted snapshot.

  • Option D: Copying the snapshots to an Amazon S3 bucket that is encrypted using server-side encryption with AWS Key Management Service (AWS KMS) managed keys (SSE-KMS) would not result in an encrypted DB instance. Amazon S3 and Amazon RDS are different services and their encryption settings are managed separately.

I hope this clarifies your doubts! If you have any more questions, feel free to ask.

相关推荐
云边云科技_云网融合15 小时前
生态共建 · 专业交付 | 我们与阿里云共建的 Landing Zone 标杆实践
阿里云·云计算
云上工程笔记18 小时前
RDMA 高速互联 GPU 云怎么选:多卡训练、分布式训练与 RoCE/InfiniBand 架构对比
架构·云计算·gpu算力
chunmiao30321 天前
阿里云Wan3.0视频大模型上线:单次生成30秒还能读文档
阿里云·云计算·音视频
yunlaodacom1 天前
阿里云国际版代理商:OSS中文文件名上传正常,下载却NoSuchKey,URL编码怎么检查
阿里云·云计算
AKAMAI2 天前
每个应用程序现在都生活在人工智能生态系统中
人工智能·云计算
财迅通Ai2 天前
科源制药携手腾讯云推进AI办公迭代升级
人工智能·云计算·腾讯云·科源制药
tg_xianheyun2 天前
腾讯云国际账号注册代充值服务商怎么选?
大数据·运维·服务器·云计算·github·腾讯云·cdn加速
liuqs3322 天前
AWS、Azure接连宕机后,“云存储”的这个软肋被重新摆上台面
云计算·azure·aws
不一样的少年_2 天前
Docker 入门第一课:从架构、云服务器到安装完成
linux·docker·云计算
聚搜云——JuSouClouD2 天前
上海阿里云代理商(聚搜云)分享:ECS 服务器 CPU 跑满 100%,如何找到占用高的进程
服务器·阿里云·云计算