Some messages in an Amazon SQS queue contain sensitive data. A developer must ensure all messages are encrypted at rest. Which solution satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable server-side encryption on the SQS queue using the SQS-managed encryption key (SSE-SQS)..
Why this is the answer
Enabling server-side encryption with SSE-SQS ensures all messages are encrypted at rest using SQS-managed keys. This directly addresses the requirement for encrypting sensitive data within the queue. Requiring HTTPS with aws:SecureTransport encrypts data in transit, not at rest. Using AWS Certificate Manager for SSL/TLS certificates also secures data in transit, not at rest. Setting a message attribute named ENCRYPT does not provide any actual encryption; it's merely metadata and doesn't enforce encryption on the SQS service level.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed