Decrypt PGP uploads in a Transfer Family workflow with the private key from Secrets Manager

Answer Correct answer: C — Store the PGP private key in Secrets Manager, add a nominal workflow step with PGP decryption parameters, and associate it with the server.

A company needs to use an AWS Transfer Family SFTP-enabled server with an Amazon S3 bucket to receive updates from a third-party data supplier. The data is encrypted with Pretty Good Privacy (PGP) encryption. The company needs a solution that will automatically decrypt the data after the company receives the data. A solutions architect will use a Transfer Family managed workflow. The company has created an IAM service role by using an IAM policy that allows access to AWS Secrets Manager and the S3 bucket. The role’s trust relationship allows the transfer amazonaws.com service to assume the role. What should the solutions architect do next to complete the solution for automatic decryption?

  1. Store the PGP public key in Secrets Manager. Add a nominal step in the Transfer Family managed workflow to decrypt files. Configure PGP encryption parameters in the nominal step. Associate the workflow with the Transfer Family server.
  2. Store the PGP private key in Secrets Manager. Add an exception-handling step in the Transfer Family managed workflow to decrypt files. Configure PGP encryption parameters in the exception handler. Associate the workflow with the SFTP user.
  3. Store the PGP private key in Secrets Manager. Add a nominal step in the Transfer Family managed workflow to decrypt files. Configure PGP decryption parameters in the nominal step. Associate the workflow with the Transfer Family server. Correct Answer
  4. Store the PGP public key in Secrets Manager. Add an exception-handling step in the Transfer Family managed workflow to decrypt files. Configure PGP decryption parameters in the exception handler. Associate the workflow with the SFTP user.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

PGP decryption needs the private key, so the private key belongs in Secrets Manager, and decryption must be a nominal workflow step that runs on every incoming file rather than an exception handler, because a failed decryption is a normal outcome the supplier's transfer can still report.

A company receives third-party data through an AWS Transfer Family SFTP-enabled server writing to an S3 bucket, and the data is PGP encrypted so it must be decrypted automatically after receipt. The company has an IAM service role that can access Secrets Manager and the bucket and that Transfer Family can assume, and a Transfer Family managed workflow will be used.

Storing the public key. The public key is used to encrypt, not to decrypt, so a workflow holding only the public key cannot recover the plaintext. Another common error is putting decryption in an exception-handling step, which only fires on failure and therefore leaves every successfully received encrypted file undecrypted.

Community Discussion (7 comments)

zapper1234 👍 7
The answer should be "C" because you store the "private" key in Secrets Manager
AzureDP900 👍 1
C and D are pretty similar however D talks about exception handling. C is right answer
mark_232323 👍 1 Selected: C
C correct
dzhang344 👍 1 Selected: C
C, for sure.
gfhbox0083 👍 3
C, for sure. In the context of AWS Transfer Family managed workflows, a ""nominal step"" refers to one of the predefined steps that you can include in a managed workflow to automate file transfer and processing tasks. An ""exception-handling step"" is a specific type of step designed to handle errors or exceptions that occur during the execution of a workflow.
grandcanyon 👍 2 Selected: C
C is correct b/c private key is what is required for decryption
Helpnosense 👍 2 Selected: C
Agree with Zapper1234 plus the permission is granted to transfer family server.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The supplier encrypts with the company's PGP public key, so only the matching private key can reverse it, and that private key is stored in AWS Secrets Manager where the Transfer Family service role already has permission to retrieve it. A nominal step in the managed workflow is the step type that runs as part of the normal processing of every file, so adding a decrypt step with PGP decryption parameters there means each arriving file is decrypted automatically as it lands. Associating the completed workflow with the Transfer Family server is what activates it for incoming transfers, so no manual step is required from the company.

Why the Other Options Are Wrong

A: The PGP public key is used to encrypt data, not to decrypt it, so a workflow holding only the public key cannot recover plaintext from the received files. B: It stores the private key correctly, but an exception-handling step only runs when the workflow detects a failure, so files that arrive and process without error would never be decrypted, which defeats the automatic decryption requirement. D: It combines both errors, using the public key and putting decryption in an exception handler. In addition, associating a workflow with an SFTP user rather than with the server does not apply it to the transfer processing described.

Community Comment Notes

The community voted 100 to 0 for C, and the top-voted comment gave the two decisive points: the private key must be the one stored in Secrets Manager, and a nominal step is the predefined step type that runs as part of normal automated file processing rather than only on failure. A separate commenter distinguished C from the similar-looking D precisely on the nominal versus exception-handling distinction.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide