Encrypt EBS by default with an instance refresh and build an encrypted Aurora cluster from a snapshot
A company is designing a new application stack. The design includes web servers and backend servers that are hosted on Amazon EC2 instances. The design also includes an Amazon Aurora MySQL DB cluster. The EC2 instances are in an Auto Scaling group that uses launch templates. The EC2 instances for the web layer and the backend layer are backed by Amazon Elastic Block Store (Amazon EBS) volumes. No layers are encrypted at rest A security engineer needs to implement encryption at rest. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
EBS encryption-by-default plus an instance refresh is the native way to encrypt previously unencrypted instances. Aurora encryption is set at creation, so an existing unencrypted cluster is migrated by snapshotting and restoring into a new KMS-encrypted cluster. Neither task uses ACM, which manages TLS certificates, not at-rest encryption.
Web and backend EC2 layers use EBS that is unencrypted, and an Aurora MySQL cluster is unencrypted. For EBS, enable EBS encryption-by-default in the Region and perform an Auto Scaling group instance refresh so existing instances are replaced by encrypted ones launched from the templates. For Aurora, you cannot encrypt an existing cluster in place; create a new KMS-encrypted cluster restored from a snapshot of the current cluster. ACM is for certificates, not storage encryption, so it does not apply.
Using ACM for EBS or Aurora encryption (options B/E)—ACM issues certificates, not KMS data keys, so it cannot encrypt storage. Or trying to apply KMS encryption to an existing Aurora cluster in place (option D), which AWS does not support; a snapshot-restore to a new encrypted cluster is required.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.