Certified Solutions Architect Data Encryption with KMS Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect Data Encryption with KMS flashcards as text
A company wants to encrypt S3 objects so that only specific IAM roles can decrypt them, even if someone gains S3 bucket access. Which KMS feature best satisfies this requirement?
Answer: SSE-KMS with a customer managed key and a restrictive key policy
SSE-KMS with a customer managed key lets you attach a key policy that explicitly lists which IAM principals can use kms:Decrypt, independent of S3 bucket permissions.
Which KMS key type allows you to import your own key material generated outside of AWS?
Answer: Customer managed key with imported key material
Customer managed keys support importing external key material, giving you full control over the cryptographic material while AWS manages the key infrastructure.
An architect needs to encrypt data at rest in RDS using KMS. What happens to the automated backups when the RDS instance uses KMS encryption?
Answer: Backups are encrypted with the same KMS key as the RDS instance
RDS automated backups, snapshots, and read replicas inherit the same KMS key used to encrypt the source RDS instance.
A Lambda function needs to decrypt a secret stored in AWS Secrets Manager. The secret is encrypted with a customer managed KMS key. What permission must the Lambda execution role have?
Answer: kms:Decrypt and secretsmanager:GetSecretValue
The Lambda execution role needs secretsmanager:GetSecretValue to retrieve the secret and kms:Decrypt to decrypt the data key that protects the secret value.
What is the maximum size of data that can be encrypted directly using a KMS CMK via the Encrypt API call?
Answer: 4 KB
KMS limits direct encryption via the Encrypt API to 4 KB; larger data must be encrypted using envelope encryption with a generated data key.
A solutions architect wants to ensure that a KMS key is never used for encryption after a specific date. Which approach is most appropriate?
Answer: Disable the KMS key on the target date
Disabling a KMS key prevents any new encrypt or decrypt operations while preserving the ability to re-enable it, which is safer and reversible compared to deletion.
When using SSE-KMS to encrypt an S3 object, which API call does S3 make to KMS on behalf of the requester during a PutObject operation?
Answer: kms:GenerateDataKey
S3 calls kms:GenerateDataKey to get a plaintext data key and an encrypted copy; S3 uses the plaintext key to encrypt the object, then discards it and stores only the encrypted key.