A company will train and host an ML model in SageMaker. All data must be encrypted at rest. The company wants AWS to maintain the root of trust for the encryption keys and to have key usage logged, while minimizing operational overhead. Which option satisfies these requirements with the least operational effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Use customer-managed AWS KMS keys to encrypt EBS volumes and S3 model artifacts..
Why this is the answer
Using customer-managed AWS KMS keys (CMKs) is the correct choice because it directly addresses all requirements with minimal operational overhead. KMS allows AWS to maintain the root of trust, provides detailed logging of key usage via CloudTrail, and encrypts both EBS volumes (used by SageMaker instances) and S3 model artifacts. While CMKs offer more control than AWS-managed keys, AWS still handles the underlying infrastructure and security of the key management service. AWS STS is for temporary credentials, not for managing encryption keys. AWS CloudHSM offers high security but significantly increases operational overhead as you manage the HSMs directly. SageMaker built-in transient keys and default EBS encryption are less flexible and don't provide the same level of control or logging for key usage as CMKs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed