A company is deploying a new application stack that includes web and backend servers on Amazon EC2 in an Auto Scaling group that uses launch templates, and an Amazon Aurora MySQL DB cluster. EBS volumes back the EC2 instances. No components are currently encrypted at rest. A security engineer must implement encryption at rest. Which combination of actions will meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable EBS default encryption in the target AWS Region and perform an Auto Scaling group instance refresh., Create a new AWS Key Management Service (AWS KMS)–encrypted Aurora DB cluster from a snapshot of the existing cluster..
Why this is the answer
The correct options address encryption for both EBS volumes and the Aurora DB cluster. Enabling EBS default encryption in the target AWS Region ensures all new EBS volumes created in that region are encrypted by default. An Auto Scaling group instance refresh will terminate existing unencrypted instances and launch new ones, which will then use encrypted EBS volumes. For Aurora, existing unencrypted DB clusters cannot be encrypted directly. The only way to encrypt an unencrypted Aurora cluster is to create a new, encrypted cluster from a snapshot of the existing one. Incorrect options: Updating launch templates with ACM encryption for EBS volumes is incorrect because ACM is for SSL/TLS certificates, not EBS volume encryption. EBS encryption is managed through KMS. Applying AWS KMS encryption directly to an existing unencrypted Aurora DB cluster is not possible; a new encrypted cluster must be created from a snapshot. Applying ACM encryption to the existing DB cluster is incorrect as ACM is for certificate management, not database encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed