Encrypt EBS by default with an instance refresh and build an encrypted Aurora cluster from a snapshot

Answer Correct answer: A, C — enable EBS encryption-by-default with an instance refresh and restore a KMS-encrypted Aurora cluster from a snapshot.

A company is designing a new application stack. The design includes web servers and backend servers that are hosted on Amazon EC2 instances. The design also includes an Amazon Aurora MySQL DB cluster. The EC2 instances are in an Auto Scaling group that uses launch templates. The EC2 instances for the web layer and the backend layer are backed by Amazon Elastic Block Store (Amazon EBS) volumes. No layers are encrypted at rest A security engineer needs to implement encryption at rest. Which combination of steps will meet these requirements? (Choose two.)

  1. Modify EBS default encryption settings in the target AWS Region to enable encryption. Use an Auto Scaling group instance refresh. Correct Answer
  2. Modify the launch templates for the web layer and the backend layer to add AWS Certificate Manager (ACM) encryption for the attached EBS volumes. Use an Auto Scaling group instance refresh.
  3. Create a new AWS Key Management Service (AWS KMS) encrypted DB cluster from a snapshot of the existing DB cluster. Correct Answer
  4. Apply AWS Key Management Service (AWS KMS) encryption to the existing DB cluster.
  5. Apply AWS Certificate Manager (ACM) encryption to the existing DB cluster.

Community Votes

AC
100%

100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EBS encryption-by-default plus an instance refresh is the native way to encrypt previously unencrypted instances. Aurora encryption is set at creation, so an existing unencrypted cluster is migrated by snapshotting and restoring into a new KMS-encrypted cluster. Neither task uses ACM, which manages TLS certificates, not at-rest encryption.

Web and backend EC2 layers use EBS that is unencrypted, and an Aurora MySQL cluster is unencrypted. For EBS, enable EBS encryption-by-default in the Region and perform an Auto Scaling group instance refresh so existing instances are replaced by encrypted ones launched from the templates. For Aurora, you cannot encrypt an existing cluster in place; create a new KMS-encrypted cluster restored from a snapshot of the current cluster. ACM is for certificates, not storage encryption, so it does not apply.

Using ACM for EBS or Aurora encryption (options B/E)—ACM issues certificates, not KMS data keys, so it cannot encrypt storage. Or trying to apply KMS encryption to an existing Aurora cluster in place (option D), which AWS does not support; a snapshot-restore to a new encrypted cluster is required.

Community Discussion (5 comments)

sema2232 👍 1
why not B?
aescudero51 👍 4 Selected: AC
A/C B - You don't use ACM for encryption, it's KMS D - You can't encrypt an existing cluster, you need to snapshot, then encrypt with KMS E - Same as B
Zek 👍 1
A,C - Agree
danish1234 👍 2 Selected: AC
AC . You can not encrypt ebs with ACM.
danish1234 👍 1
AC . All other options are joke.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A enables EBS encryption-by-default in the Region and triggers an Auto Scaling group instance refresh, replacing instances with encrypted EBS volumes. C creates a new KMS-encrypted Aurora cluster from a snapshot of the existing one, the supported path since Aurora encryption cannot be added to a live cluster. Both meet encryption-at-rest with native mechanisms.

Why the Other Options Are Wrong

B and E propose ACM encryption for EBS/Aurora; ACM manages certificates, not storage encryption, so they are invalid. D tries to encrypt an existing cluster in place, which Aurora does not allow—snapshot-and-restore to an encrypted cluster (C) is required. A and C are the correct pair.

Community Comment Notes

Community voted A,C (100). Commenters stressed you cannot encrypt EBS with ACM and cannot encrypt an existing Aurora cluster directly—snapshot to a KMS-encrypted cluster is needed. B, D, and E were dismissed as invalid or impossible.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide