Answer – A, C, and D
Amazon EBS encryption offers a simple encryption solution for your EBS volumes without the need to build, maintain, and secure your own key management infrastructure. When you create an encrypted EBS volume and attach it to a supported instance type, the following types of data are encrypted:
(i) Data at rest inside the volume
(ii) All data moving between the volume and the instance
(iii) All snapshots created from the volume
(iv) All volumes created from those snapshots
Based on this, options A, C, and D are all CORRECT.
Option B is incorrect since the data that is copied to S3 is not encrypted.
For more information on this, please visit the link below.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html