Deploy the tokenization code on AWS Nitro Enclaves for an isolated, attestable environment
A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers. The application will send the credit card numbers to a component that is running in an isolated environment. The component will encrypt, store, and decrypt the numbers. The component then will issue tokens to replace the numbers in other parts of the application. The component of the application that manages the tokenization process will be deployed on a separate set of EC2 instances. Other components of the application must not be able to store or access the credit card numbers. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Nitro Enclaves (D) are isolated, hardened VMs with no persistent storage, no external networking, and no operator access, verified by cryptographic attestation—ideal for processing highly sensitive data like PANs. Dedicated Instances (A) are just tenancy isolation, not data isolation; a partition placement group (B) is for spread, not security; a separate VPC (C) still allows network reachability and operator access. D is the only true isolation control.
Credit-card tokenization must run in an isolated environment that other application components cannot reach, handling encryption, storage, decryption, and token issuance. AWS Nitro Enclaves provide a hardened, isolated compute environment attached to an EC2 instance with no external interaction, no operator access, and cryptographic attestation, so only the tokenization code can see the PANs while the rest of the app cannot store or access them.
Using Dedicated Instances (A)—that only controls hardware tenancy, not data isolation from other components. A partition placement group (B)—a placement strategy for fault isolation, not sensitive-data isolation. A separate VPC (C)—network isolation but components can still be reached and operators can access them; not the hardened, attestable boundary Nitro Enclaves provide.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.