Q & A
The answers to these questions appear in Appendix A. Use the Pearson Test Prep Software Online for more practice with exam format questions.
1. Which AWS storage service is available with AWS as a single-tenant storage design?
2. What is the default state of an S3 bucket regarding public access when the bucket is first created?
3. What is the security advantage of using SSE-C encryption with Amazon S3 buckets?
4. Describe the concept of envelope encryption that KMS uses.
5. What type of data stored at AWS is always automatically encrypted by default?
6. Why is AWS CloudHSM chosen by companies that must adhere to a high compliance standard?
7. How does AWS KMS carry out automatic key rotation for imported keys?
8. Where can private CAs created by AWS Certificate Manager be deployed?