A compliance audit found that some Amazon EBS volumes in an AWS account were created unencrypted. You must ensure that all new EBS volumes are encrypted at rest with the LEAST amount of effort. Which approach meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable EBS encryption by default in all AWS Regions..
Why this is the answer
Enabling EBS encryption by default in all AWS Regions is the most straightforward and least effort approach. This setting automatically encrypts all new EBS volumes and snapshot copies created in that Region, using your default KMS key or a specified customer managed key. This proactively prevents the creation of unencrypted volumes, addressing the compliance issue at its source. Creating an EventBridge rule with a Lambda function to delete noncompliant volumes is reactive and results in data loss. Using AWS Audit Manager is for compliance reporting and evidence collection, not for enforcing encryption. Creating an AWS Config rule with Systems Manager Automation to encrypt volumes is also reactive and more complex than simply enabling default encryption. It would involve additional steps to encrypt existing unencrypted volumes, rather than preventing their creation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed