Deploy the tokenization code on AWS Nitro Enclaves for an isolated, attestable environment

Answer Correct answer: D — deploy the tokenization code on AWS Nitro Enclaves for an isolated, attestable environment that other components cannot reach.

A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers. The application will send the credit card numbers to a component that is running in an isolated environment. The component will encrypt, store, and decrypt the numbers. The component then will issue tokens to replace the numbers in other parts of the application. The component of the application that manages the tokenization process will be deployed on a separate set of EC2 instances. Other components of the application must not be able to store or access the credit card numbers. Which solution will meet these requirements?

  1. Use EC2 Dedicated Instances for the tokenization component of the application.
  2. Place the EC2 instances that manage the tokenization process into a partition placement group.
  3. Create a separate VPDeploy new EC2 instances into the separate VPC to support the data tokenization.
  4. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Nitro Enclaves (D) are isolated, hardened VMs with no persistent storage, no external networking, and no operator access, verified by cryptographic attestation—ideal for processing highly sensitive data like PANs. Dedicated Instances (A) are just tenancy isolation, not data isolation; a partition placement group (B) is for spread, not security; a separate VPC (C) still allows network reachability and operator access. D is the only true isolation control.

Credit-card tokenization must run in an isolated environment that other application components cannot reach, handling encryption, storage, decryption, and token issuance. AWS Nitro Enclaves provide a hardened, isolated compute environment attached to an EC2 instance with no external interaction, no operator access, and cryptographic attestation, so only the tokenization code can see the PANs while the rest of the app cannot store or access them.

Using Dedicated Instances (A)—that only controls hardware tenancy, not data isolation from other components. A partition placement group (B)—a placement strategy for fault isolation, not sensitive-data isolation. A separate VPC (C)—network isolation but components can still be reached and operators can access them; not the hardened, attestable boundary Nitro Enclaves provide.

Community Discussion (3 comments)

IPLogic 👍 1 Selected: D
The best solution to meet these requirements is: D. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances. AWS Nitro Enclaves provide an isolated environment that is ideal for processing sensitive data, such as credit card numbers. They offer strong security guarantees by isolating the tokenization process from other components of the application, ensuring that sensitive data is protected and inaccessible to unauthorized components
VPNalumni 👍 1
D. Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances. Explanation: AWS Nitro Enclaves provide isolated compute environments to process highly sensitive data, ensuring that other components cannot access the credit card numbers. Nitro Enclaves are specifically designed for secure processing of confidential information, making them ideal for tokenization tasks. https://aws.amazon.com/ec2/nitro/nitro-enclaves/
mikelord 👍 1
Option D, deploying the tokenization component onto AWS Nitro Enclaves, is the best solution. Nitro Enclaves provide a highly secure, isolated environment that can handle the encryption, storage, and tokenization of sensitive information without exposing it to other parts of the application, meeting the requirements for both isolation and data security.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Nitro Enclaves provide an isolated compute environment for EC2 with no external interaction, no persistent storage, and no operator or application access except through a local vsock channel, all verifiable via cryptographic attestation. Deploying the tokenization code there ensures only that enclave can process the credit-card numbers, while other components of the application cannot store or access them—meeting the isolation requirement.

Why the Other Options Are Wrong

A (Dedicated Instances) only affects hardware tenancy, not data isolation between components. B (partition placement group) is a fault-isolation placement strategy, not a security boundary. C (separate VPC) provides network separation but instances remain reachable and operator-accessible, unlike the enclave's hardened, attestable boundary. D is correct.

Community Comment Notes

Community voted D (100). Commenters described Nitro Enclaves as an isolated, attestable environment purpose-built for processing highly sensitive data like credit-card numbers, keeping them away from other application components. D confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide