Question 15 of 19
Single answerA security engineer needs to implement a solution to create and control the keys that a company uses for generated and used within a custom key store that is backed by an AWS CloudHSM cluster. The security engineer will use symmetric and asymmetric data key pairs for local use within applications. The security engineer also must audit the use of the keys. How can the security engineer meet these requirements?
ATo create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use Amazon Athena.
BTo create the keys, use Amazon S3 and the custom key stores with the CloudHSM cluster. For auditing, use AWSCloudTrail.
CTo create the keys, use AWS Key Management Service (AwS KMS) and the custom key stores with the CloudHSM cluster. For audliting, use Amazon GuardDuty.
✓DTo create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use AWS CloudTrail.
✓
Correct Answer: D
To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use AWS CloudTrail.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of AWS certification topics.