kms Flashcards

1
Q

You need need to re-encrypt a file with a new customer master key, which API call can you use to do this?

enable-key-rotation

decrypt and encrypt

encrypt

re-encrypt

A

re-encrypt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following is an encrypted key used by KMS to encrypt your data?

Envelope Key

Customer Master Key

Encryption Key

Customer Managed Key

A

Envelope Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of the following is a managed service that allows you to create and control the encryption keys used to encrypt your data?

KMS

RDS Encryption

S3 Encryption

CMS

A

KMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following statements are correct? (Choose 2)

The Envelope Key or Data Key is used to encrypt and decrypt plain text files

The Customer Master Key is used to encrypt and decrypt the Envelope Key or Data Key

The Envelope Key or Data Key is used to encrypt and decrypt the Customer Master Key

The Customer Master Key is used to encrypt and decrypt plain text files

A

The Envelope Key or Data Key is used to encrypt and decrypt plain text files

The Customer Master Key is used to encrypt and decrypt the Envelope Key or Data Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

You are working on a project which requires a Key Management Solution. Your Security Architect has confirmed that a multi-tenant solution is fine. Which solution do you recommend?

S3 Encryption

KMS

CloudHSM

Client Side Encryption

A

KMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

You would like KMS to rotate your encryption keys on a yearly basis, which API command can you use to configure this?

configure-key-rotation

chkconfig key-rotation on

enable-key-rotation

setup-key-rotation -y

A

enable-key-rotation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of the following statements is correct in relation to KMS? (Choose 2)

KMS encryption keys are global

KMS encryption keys are regional

You can export your customer master key

You cannot export you customer master key

A

KMS encryption keys are regional

You cannot export you customer master key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which command can you use to encrypt a plain text file using a CMK?

aws iam encrypt

aws kms encrypt

aws encrypt

aws kms-encrypt

A

aws kms encrypt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly