Decrypt PGP uploads in a Transfer Family workflow with the private key from Secrets Manager
A company needs to use an AWS Transfer Family SFTP-enabled server with an Amazon S3 bucket to receive updates from a third-party data supplier. The data is encrypted with Pretty Good Privacy (PGP) encryption. The company needs a solution that will automatically decrypt the data after the company receives the data. A solutions architect will use a Transfer Family managed workflow. The company has created an IAM service role by using an IAM policy that allows access to AWS Secrets Manager and the S3 bucket. The role’s trust relationship allows the transfer amazonaws.com service to assume the role. What should the solutions architect do next to complete the solution for automatic decryption?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
PGP decryption needs the private key, so the private key belongs in Secrets Manager, and decryption must be a nominal workflow step that runs on every incoming file rather than an exception handler, because a failed decryption is a normal outcome the supplier's transfer can still report.
A company receives third-party data through an AWS Transfer Family SFTP-enabled server writing to an S3 bucket, and the data is PGP encrypted so it must be decrypted automatically after receipt. The company has an IAM service role that can access Secrets Manager and the bucket and that Transfer Family can assume, and a Transfer Family managed workflow will be used.
Storing the public key. The public key is used to encrypt, not to decrypt, so a workflow holding only the public key cannot recover the plaintext. Another common error is putting decryption in an exception-handling step, which only fires on failure and therefore leaves every successfully received encrypted file undecrypted.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The supplier encrypts with the company's PGP public key, so only the matching private key can reverse it, and that private key is stored in AWS Secrets Manager where the Transfer Family service role already has permission to retrieve it. A nominal step in the managed workflow is the step type that runs as part of the normal processing of every file, so adding a decrypt step with PGP decryption parameters there means each arriving file is decrypted automatically as it lands. Associating the completed workflow with the Transfer Family server is what activates it for incoming transfers, so no manual step is required from the company.Why the Other Options Are Wrong
A: The PGP public key is used to encrypt data, not to decrypt it, so a workflow holding only the public key cannot recover plaintext from the received files. B: It stores the private key correctly, but an exception-handling step only runs when the workflow detects a failure, so files that arrive and process without error would never be decrypted, which defeats the automatic decryption requirement. D: It combines both errors, using the public key and putting decryption in an exception handler. In addition, associating a workflow with an SFTP user rather than with the server does not apply it to the transfer processing described.Community Comment Notes
The community voted 100 to 0 for C, and the top-voted comment gave the two decisive points: the private key must be the one stored in Secrets Manager, and a nominal step is the predefined step type that runs as part of normal automated file processing rather than only on failure. A separate commenter distinguished C from the similar-looking D precisely on the nominal versus exception-handling distinction.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →