Which of the following methods can be used to encrypt objects at rest in Amazon S3? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Server-side encryption with Amazon S3–managed keys (SSE-S3), Server-side encryption with AWS KMS–managed keys (SSE-KMS).
Why this is the answer
Server-side encryption with Amazon S3–managed keys (SSE-S3) and Server-side encryption with AWS KMS–managed keys (SSE-KMS) are two primary methods for encrypting objects at rest in Amazon S3. SSE-S3 uses keys managed entirely by AWS, providing a simple encryption solution where S3 handles key management. SSE-KMS uses AWS Key Management Service (KMS) to manage encryption keys, offering more control over key usage and auditing capabilities. TLS and SSL are protocols used for encryption in transit, not at rest. Transparent Data Encryption (TDE) is a database encryption technology, not directly applicable to S3 object encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed