Encrypt the 2 KB file directly with the aws kms encrypt command

Answer Correct answer: A — a 2 KB file is within KMS Encrypt's 4 KB limit, so encrypt it directly with the existing CMK.

A company runs a cron job on an Amazon EC2 instance on a predefined schedule. The cron job calls a bash script that encrypts a 2 KB file. A security engineer creates an AWS Key Management Service (AWS KMS) customer managed key with a key policy. The key policy and the EC2 instance role have the necessary configuration for this job. Which process should the bash script use to encrypt the file?

  1. Use the aws kms encrypt command to encrypt the file by using the existing KMS key. Correct Answer
  2. Use the aws kms create-grant command to generate a grant for the existing KMS key.
  3. Use the aws kms encrypt command to generate a data key. Use the plaintext data key to encrypt the file.
  4. Use the aws kms generate-data-key command to generate a data key. Use the encrypted data key to encrypt the file.

Community Votes

A
56%
D
44%

56% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

KMS Encrypt operates on plaintext up to 4 KB, so a 2 KB payload fits without generating a data key. For this small, single-file, scheduled job the direct Encrypt call is the simplest valid process; envelope encryption (generate-data-key) is preferred at scale but is not required here, and option D's wording (encrypt with the encrypted data key) is itself incorrect—you encrypt with the plaintext data key.

A cron job encrypts a small 2 KB file using a configured KMS customer managed key. The AWS KMS Encrypt API accepts plaintext up to 4,096 bytes, so a 2 KB file is within the limit and can be encrypted directly with aws kms encrypt using the existing key, with no need for a data key, grant, or envelope-encryption machinery.

Choosing option D, which describes encrypting the file with the encrypted data key—that is wrong; you must use the plaintext data key to encrypt and store the encrypted data key alongside. For a 2 KB file, direct `aws kms encrypt` (option A) is both valid and simpler.

Community Discussion (5 comments)

nznzwell 👍 1 Selected: A
D is not correct: "Use the encrypted data key to encrypt the file." you need to use the plaintext data key to encrypt the file, not the encrypted data key. A is the correct answer.
TareDHakim 👍 2 Selected: D
option A could encrypt the 2 KB file in this scenario, however, this approach is less efficient for frequent encryption operations and does not use envelope encryption, which is more scalable and secure.
Pmktechno 👍 2 Selected: D
Generate a Data Key: The aws kms generate-data-key command generates a data key that includes both a plaintext version and an encrypted version of the key. Encrypt the File: Use the plaintext data key to encrypt the 2 KB file. Store the Encrypted Data Key: Store the encrypted data key alongside the encrypted file. This allows the file to be decrypted later using the encrypted data key and the KMS key. This approach is efficient and secure, as it leverages the strengths of both KMS for key management and local encryption for performance.
723993f 👍 2 Selected: A
2 kb file only, no need for grant, no need to for data key
DSExam 👍 2 Selected: A
The file of 2k is well within the 4k limit of the AWS KMS encrypt command

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The file is 2 KB, well under the 4 KB ceiling of the KMS Encrypt API, and the key policy plus instance role are already configured for the job. The bash script can call aws kms encrypt with the existing CMK to encrypt the file directly, which is the correct and simplest process for a small payload.

Why the Other Options Are Wrong

B (create-grant) is unnecessary—no additional delegated permissions are needed for a direct encrypt call. D is wrong as written: you encrypt the file with the plaintext data key, not the encrypted data key, and for a 2 KB file direct Encrypt is simpler than envelope encryption. A is the valid choice; the 2 KB size removes any need for a data key.

Community Comment Notes

Community favored A (56) over D (44). A supporters noted the 2 KB file is within the 4 KB Encrypt limit and needs no data key, while a commenter pointed out D's wording—encrypting with the encrypted data key—is incorrect; you use the plaintext data key. D supporters favored envelope encryption but overcomplicated a small-file job.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide