Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam DBS-C01 Topic 1 Question 84 Discussion

Actual exam question for Amazon's DBS-C01 exam
Question #: 84
Topic #: 1
[All DBS-C01 Questions]

A company uses an Amazon Redshift cluster to run its analytical workloads. Corporate policy requires that the company's data be encrypted at rest with customer managed keys. The company's disaster recovery plan requires that backups of the cluster be copied into another AWS Region on a regular basis.

How should a database specialist automate the process of backing up the cluster data in compliance with these policies?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the Amazon Redshift documentation1, you can enable database encryption for your clusters to help protect data at rest. You can use either AWS Key Management Service (AWS KMS) or a hardware security module (HSM) to manage the top-level encryption keys in this hierarchy. The process that Amazon Redshift uses for encryption differs depending on how you manage keys.

To copy encrypted snapshots across Regions, you need to create a snapshot copy grant in the destination Region and specify a CMK in that Region. You also need to configure cross-Region snapshots in the source Region and provide the destination Region, the snapshot copy grant, and retention periods for the snapshots. This way, you can automate the process of backing up the cluster data in compliance with the corporate policies.


Contribute your Thoughts:

Nathan
24 days ago
Alright, I think we've got a good handle on this one. Let's go with either Option B or C as the most robust and compliant solutions. What do you all think?
upvoted 0 times
...
Craig
25 days ago
Yeah, that would be way too straightforward. Where's the fun in that? I'm glad the options are a bit more involved, it really makes us think through the different approaches.
upvoted 0 times
...
Billi
26 days ago
Hah, can you imagine if the answer was Option D? 'Use the same customer-supplied key materials to create a CMK with the same private key in the destination Region.' That would just be too easy, right?
upvoted 0 times
Stephane
6 days ago
Agreed. It's important to follow best practices to ensure data security and continuity in case of any unforeseen events.
upvoted 0 times
...
Valentin
7 days ago
Definitely. The devil is in the details when it comes to compliance and disaster recovery planning.
upvoted 0 times
...
Josefa
8 days ago
Yeah, but I think it's better to go with the more detailed options like A) or B) for better compliance and automation.
upvoted 0 times
...
Sylvie
9 days ago
I see. Option D) is about using the same key to create a CMK in the destination Region, configuring cross-Region snapshots, and specifying the corresponding CMK in the destination Region. It does sound straightforward.
upvoted 0 times
...
Rima
10 days ago
Option C) involves copying the AWS KMS key to the destination Region, setting up S3 buckets in each Region, using Amazon EventBridge to schedule an AWS Lambda function for copying the snapshot, and configuring S3 Cross-Region Replication.
upvoted 0 times
...
Elly
11 days ago
That sounds like a good option. Option B) also seems plausible. It suggests creating a new AWS Key Management Service (AWS KMS) customer managed key in the destination Region and setting up cross-Region snapshots for the Amazon Redshift cluster.
upvoted 0 times
...
Aimee
12 days ago
I think the answer is A) Copy the AWS Key Management Service (AWS KMS) customer managed key from the source Region to the destination Region. Set up an AWS Glue job in the source Region to copy the latest snapshot of the Amazon Redshift cluster from the source Region to the destination Region. Use a time-based schedule in AWS Glue to run the job on a daily basis.
upvoted 0 times
...
...
Leatha
27 days ago
Sounds good to me. Now let's just hope the real exam question isn't something completely unexpected, like 'What's the square root of 42?' or something equally random.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77