A data engineer is starting an Amazon EMR cluster. The dataset to load into the cluster resides in an Amazon S3 bucket and is encrypted with an AWS KMS key. An S3 path contains a PEM file for in-transit encryption. Which approach satisfies the requirement that data be encrypted both at rest and in transit?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon EMR security configuration. Specify the appropriate AWS KMS key for at-rest encryption for the S3 bucket. Specify the Amazon S3 path of the PEM file for in-transit encryption. Use the security configuration during EMR cluster creation..
Why this is the answer
The correct answer is to create a single Amazon EMR security configuration that specifies both the AWS KMS key for at-rest encryption of data in S3 and the S3 path to the PEM file for in-transit encryption. This consolidated security configuration is then applied when creating the EMR cluster. EMR security configurations are designed to centralize encryption settings, allowing you to define both at-rest and in-transit encryption within a single configuration object. The first incorrect option suggests creating two separate security configurations and attaching both, which is not how EMR security configurations are designed to be used for combined encryption settings. The second incorrect option mentions "local disk encryption for the S3 bucket," which is a misstatement; KMS keys are used for S3 object encryption, not local disk encryption of the S3 bucket itself. The fourth option is functionally identical to the correct answer, but the phrasing "Use the security configuration during EMR cluster creation" is slightly more precise than "attach the security configuration to the cluster" in the context of EMR's console/API workflows.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed