Q203. An advisory firm is creating a secure data analytics solution for its regulated financial services users. Users will upload their raw data to an Amazon S3 bucket where they have PutObject permissions only. Data will be an

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q203. An advisory firm is creating a secure data analytics solution for its regulated financial services users. Users will upload their raw data to an Amazon S3 bucket where they have PutObject permissions only. Data will be analyzed by applications running on an Amazon EMR cluster launched in a VPC. The firm requires that the environment be isolated from the internet. All data at rest must be encrypted using keys controlled by the firm.Which combination of actions should the Solutions Architect take to meet the user's security requirements? (Choose two.)

A.Launch the Amazon EMR cluster in a private subnet configured to use an AWS KMS CMK for at- rest encryption.Configure a gateway VPC endpoint for Amazon S3 and an interface VPC endpoint for AWS KMS.
B.Launch the Amazon EMR cluster in a private subnet configured to use an AWS KMS CMK for at- rest encryption.Configure a gateway VPC endpoint for Amazon S3 and a NAT gateway to access AWS KMS.
C.Launch the Amazon EMR cluster in a private subnet configured to use an AWS CloudHSM appliance for at-rest encryption.Configure a gateway VPC endpoint for Amazon S3 and an interface VPC endpoint for CloudHSM.
D.Configure the S3 endpoint policies to permit access to the necessary data buckets only.
E.Configure the S3 bucket policies to permit access using an aws:sourceVpce condition to match the S3 endpoint ID.
正确答案AE
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top