Design Secure Architectures Practice Question
Question
For a public application, an architect is reviewing KMS keys requirement set 3. Which design choice best fits the requirement while following AWS architectural best practices?
Answer choices
- A. Place all components on a single large instance to simplify troubleshooting.
- B. Use long-lived access keys in application configuration so services can call AWS APIs directly.
- C. Disable monitoring until the workload reaches steady production traffic.
- D. Encrypt data with customer managed keys when key policy control or rotation is required.
Correct Answer
D. Encrypt data with customer managed keys when key policy control or rotation is required.
Explanation
The best answer applies KMS keys: encrypt data with customer managed keys when key policy control or rotation is required. The other options increase operational risk, weaken security, or remove observability that an AWS Solutions Architect should preserve.
Question details
- Difficulty: hard
- Domain: Design Secure Architectures
- Objective: KMS keys