ExamQuestions.com

Register
Login
AWS Certified Big Data Specialty (Expired on July 1, 2020) Exam Questions

Amazon

AWS Certified Big Data Specialty (Expired on July 1, 2020)

370 / 370

Question 370:

A company needs to use a Redshift cluster in AWS. The mandate is that all data is encrypted at rest. It also needs to be ensured that the keys used for encryption for the Redshift cluster are from an on-premise HSM device. Which of the following are most secure and cost-effective solutions? Choose 2 answers from the options given below

Answer options:

A.Create a VPN connection between the VPC holding the cluster and the On-premise network
B.Create a Direct Connect connection between the VPC holding the cluster and the On-premise network
C.Use client and server certificates to configure a trusted connection between Amazon Redshift and your HSM
D.Import the keys from the on-premise HSM device to KMS