Who Manages Aurora Database and Snapshot Encryption?

Understand the AWS shared responsibility model. Understand AWS Cloud security, governance, and compliance concepts.
Answer Correct answer: B — The company configures encryption for Aurora database clusters and snapshots, while AWS secures the underlying infrastructure.

A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups. Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility model?

  1. AWS
  2. The company Correct Answer
  3. AWS Marketplace partners
  4. Third-party partners

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the customer-versus-AWS split for encryption at rest in a managed database; the trap is assuming Aurora's fully managed nature transfers encryption configuration to AWS.

Under the AWS shared responsibility model, the customer configures encryption for Amazon Aurora database clusters and snapshots, while AWS secures the underlying infrastructure. This page confirms that the company, not AWS or third-party partners, owns Aurora database and backup encryption settings.

Choosing AWS (A) because Aurora is fully managed, when AWS only provides the service, KMS integration, and infrastructure while the company enables and manages encryption for clusters and snapshots.

Community Discussion (11 comments)

zhanlp 👍 1 Selected: A
I think its a,Amazon Aurora is a managed database service
BlueMan93 👍 1 Selected: B
In the AWS Shared Responsibility Model, you, the customer, are responsible for database encryption. While AWS provides the infrastructure and underlying security of the cloud, you are responsible for securing your data, applications, and access within the AWS environment, which includes encryption.
ShaiTay 👍 1 Selected: B
B. The company
Kilobay1 👍 1 Selected: A
Amazon Aurora is a managed database service
deka96 👍 1
Amazon Aurora is a fully managed relational DB, so as far as I understand the encryption of data is responsability of AWS
Eromo 👍 2
i also think its B AWS provides the tools and services (like AWS Key Management Service (KMS)) to help manage encryption. The company must configure and manage the encryption of the database clusters and database snapshots
geocis 👍 2 Selected: B
You are responsible for the configuration and management of the provided encryption settings.
Prodyna 👍 1
B. The company While AWS provides the underlying infrastructure and encryption tools (such as AWS Key Management Service), it is the company's responsibility to configure and manage the encryption of their data, including databases and backups.
Lin878 👍 2 Selected: B
Correct answer is B
1135e0e 👍 3 Selected: B
B. The company AWS ensures the infrastructure and services are secure, but the customer must implement and manage encryption settings for their databases and snapshots.
Zerro 👍 3 Selected: B
I think the correct answer is B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Under the AWS shared responsibility model, AWS is responsible for security of the cloud, while the customer is responsible for security in the cloud. For Amazon Aurora, AWS provides the managed infrastructure and integrates encryption with AWS KMS, but the company must enable and configure encryption for database clusters and snapshots. Aurora being a managed service does not transfer data-protection configuration to AWS; the customer chooses the KMS key and whether backups are encrypted. Therefore, option B is correct: the company manages Aurora cluster and snapshot encryption.

Why the Other Options Are Wrong

Option A is incorrect because AWS operates the physical hosts, network, and managed-service software, not the customer's encryption settings or key policy. Options C and D are incorrect because AWS Marketplace partners and third-party partners are not parties to the AWS shared responsibility model for a native Aurora database; they might supply software, but they do not manage Aurora encryption by default. Anyone selecting A usually assumes that "fully managed" means "AWS encrypts everything," but the shared responsibility model explicitly leaves data encryption configuration to the customer.

Community Comment Notes

Most commenters, including Zerro and Lin878, agree that the correct answer is B and stress that AWS provides tools while the company configures encryption. As Eromo noted, "The company must configure and manage the encryption" for Aurora clusters and snapshots. BlueMan93 similarly explains that the customer is responsible for securing data and access, including encryption, even though AWS secures the infrastructure. A few voices such as zhanlp and Kilobay1 argued for A by pointing out that Aurora is managed, but that reasoning overlooks the customer's encryption duties.

Official Reference

Exam Strategy

On shared responsibility questions, separate security OF the cloud from security IN the cloud: AWS manages the hardware and managed-service patching, while you configure data protection features such as Aurora encryption and KMS keys. If an option names a partner or marketplace seller, eliminate it unless the question explicitly involves third-party software.

Frequently Asked Questions

Why is AWS not responsible for Aurora encryption if Aurora is managed?

AWS manages the infrastructure and provides encryption tools such as KMS, but the customer controls whether Aurora clusters and snapshots are encrypted. The shared responsibility model keeps data protection configuration with the company.

How does AWS KMS fit into Aurora encryption responsibilities?

AWS KMS supplies and protects the keys, but the company creates or selects the KMS key and enables encryption on the Aurora cluster and its snapshots. Key management permissions and rotation settings remain customer responsibilities.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide