A library stores members' face images in an S3 bucket and uses Amazon Rekognition CompareFaces to match live images to stored images. The library requires that images be encrypted at rest and encrypted in transit when used by Rekognition, and must ensure the images are not used to improve Rekognition as a service. Which architecture meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable server-side encryption on the S3 bucket and submit an AWS Support request to opt out of allowing images to be used to improve the Rekognition service, following the process AWS Support provides..
Why this is the answer
The correct option addresses all requirements directly. Enabling server-side encryption on the S3 bucket ensures encryption at rest for the stored images. Rekognition automatically encrypts data in transit when processing images. To prevent images from being used for service improvement, AWS provides an opt-out mechanism, typically initiated via an AWS Support request. Migrating to a Rekognition collection and using IndexFaces/SearchFacesByImage is a valid approach for face recognition but doesn't inherently address the opt-out requirement for service improvement or the encryption in transit aspect as comprehensively as the correct option. Using AWS GovCloud (US) or a VPN might enhance security but doesn't directly fulfill the Rekognition service improvement opt-out or the specific encryption requirements for S3 and Rekognition. Client-side encryption for S3 is an option for encryption at rest but adds complexity and doesn't address the Rekognition service improvement opt-out.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed