Who Manages Aurora Database and Snapshot Encryption?
A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups. Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility model?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the customer-versus-AWS split for encryption at rest in a managed database; the trap is assuming Aurora's fully managed nature transfers encryption configuration to AWS.
Under the AWS shared responsibility model, the customer configures encryption for Amazon Aurora database clusters and snapshots, while AWS secures the underlying infrastructure. This page confirms that the company, not AWS or third-party partners, owns Aurora database and backup encryption settings.
Choosing AWS (A) because Aurora is fully managed, when AWS only provides the service, KMS integration, and infrastructure while the company enables and manages encryption for clusters and snapshots.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Under the AWS shared responsibility model, AWS is responsible for security of the cloud, while the customer is responsible for security in the cloud. For Amazon Aurora, AWS provides the managed infrastructure and integrates encryption with AWS KMS, but the company must enable and configure encryption for database clusters and snapshots. Aurora being a managed service does not transfer data-protection configuration to AWS; the customer chooses the KMS key and whether backups are encrypted. Therefore, option B is correct: the company manages Aurora cluster and snapshot encryption.Why the Other Options Are Wrong
Option A is incorrect because AWS operates the physical hosts, network, and managed-service software, not the customer's encryption settings or key policy. Options C and D are incorrect because AWS Marketplace partners and third-party partners are not parties to the AWS shared responsibility model for a native Aurora database; they might supply software, but they do not manage Aurora encryption by default. Anyone selecting A usually assumes that "fully managed" means "AWS encrypts everything," but the shared responsibility model explicitly leaves data encryption configuration to the customer.Community Comment Notes
Most commenters, including Zerro and Lin878, agree that the correct answer is B and stress that AWS provides tools while the company configures encryption. As Eromo noted, "The company must configure and manage the encryption" for Aurora clusters and snapshots. BlueMan93 similarly explains that the customer is responsible for securing data and access, including encryption, even though AWS secures the infrastructure. A few voices such as zhanlp and Kilobay1 argued for A by pointing out that Aurora is managed, but that reasoning overlooks the customer's encryption duties.Official Reference
Exam Strategy
On shared responsibility questions, separate security OF the cloud from security IN the cloud: AWS manages the hardware and managed-service patching, while you configure data protection features such as Aurora encryption and KMS keys. If an option names a partner or marketplace seller, eliminate it unless the question explicitly involves third-party software.
Frequently Asked Questions
Why is AWS not responsible for Aurora encryption if Aurora is managed?
AWS manages the infrastructure and provides encryption tools such as KMS, but the customer controls whether Aurora clusters and snapshots are encrypted. The shared responsibility model keeps data protection configuration with the company.
How does AWS KMS fit into Aurora encryption responsibilities?
AWS KMS supplies and protects the keys, but the company creates or selects the KMS key and enables encryption on the Aurora cluster and its snapshots. Key management permissions and rotation settings remain customer responsibilities.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →