Question 1 · choose 1
Many teams launch Amazon EC2 instances in eu-west-1 from their own launch templates and scripts. A new policy requires that every new Amazon EBS volume created in the Region from now on is encrypted at rest, without asking the teams to change their templates or scripts. What should the operations team do?
- ATurn on default encryption for the account's Amazon S3 buckets
- BTurn on EBS encryption by default in eu-west-1
- CTurn on automatic key rotation for the AWS managed key that EBS uses
- DUse Elastic Volumes to change every new unencrypted volume to encrypted
Show the answer and why
ATurn on default encryption for the account's Amazon S3 buckets
Incorrect
Default bucket encryption applies to objects in S3. It does not affect EBS volumes or snapshots.
BTurn on EBS encryption by default in eu-west-1
Correct
Encryption by default is a Region-specific setting that makes new EBS volumes and snapshot copies in that Region encrypted, with no change to how they are launched.
CTurn on automatic key rotation for the AWS managed key that EBS uses
Incorrect
AWS KMS already rotates AWS managed keys every year, and rotation cannot be turned on or off for them. Rotation does not encrypt unencrypted volumes either.
DUse Elastic Volumes to change every new unencrypted volume to encrypted
Incorrect
An existing unencrypted volume cannot be encrypted directly; it takes a snapshot and a new encrypted volume, one at a time.
One Region setting covers every launch path. It has no effect on existing volumes, which still need the snapshot-and-copy route.
AWS documentation