You must train and host a SageMaker model using sensitive customer data that must be encrypted at rest. The company wants AWS to maintain the root of trust for the keys but also requires that all key usage is logged. Which encryption approach satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use customer-managed keys in AWS Key Management Service (KMS) to encrypt the ML data volumes and to encrypt model artifacts and S3 data..
Why this is the answer
Customer-managed keys in AWS KMS (CMKs) meet all requirements. AWS KMS provides encryption keys where AWS maintains the root of trust, and all key usage is automatically logged to AWS CloudTrail. You can specify a CMK for encrypting SageMaker ML storage volumes (EBS) and for encrypting model artifacts and data stored in S3. AWS CloudHSM keys would provide customer control over the root of trust, which contradicts the requirement for AWS to maintain it. SageMaker built-in transient keys are not customer-managed and do not provide detailed logging. STS temporary tokens are for authentication and authorization, not for data encryption at rest.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed