Subdomain 1.3: Use data stores in application development
1.Which two statements about how DynamoDB stores and encrypts data at rest are correct? (Select TWO.)(Select 2)
- A.DynamoDB encrypts all table data at rest by default using an AWS-owned key at no additional cost, and this can optionally be changed to an AWS managed or customer managed KMS key
- B.DynamoDB does not encrypt data at rest by default; a developer must explicitly enable server-side encryption before creating the table or the data remains in plaintext
- C.DynamoDB only encrypts data at rest for tables using provisioned capacity mode, while every on-demand table stores its attribute values unencrypted
- D.DynamoDB requires a customer managed KMS key to be specified at table creation, and there is no default AWS-owned key option available for any table
- E.When a customer managed KMS key replaces the default AWS-owned key, no application code changes are needed, since DynamoDB transparently decrypts data on access
Show answer & explanation
Correct answers: A, E — DynamoDB encrypts all table data at rest by default using an AWS-owned key at no additional cost, and this can optionally be changed to an AWS managed or customer managed KMS key; When a customer managed KMS key replaces the default AWS-owned key, no application code changes are needed, since DynamoDB transparently decrypts data on access
- A. AWS documentation states that DynamoDB encrypts all customer data at rest by default using an AWS-owned key with no additional charge, and developers can optionally switch to an AWS managed key or a customer managed key for more control.
- B. Encryption at rest is not an opt-in feature that must be explicitly enabled; every DynamoDB table has encryption at rest applied automatically from creation, regardless of whether the developer configures anything.
- C. Encryption at rest applies uniformly to DynamoDB tables regardless of capacity mode; there is no distinction between provisioned and on-demand tables in whether data is encrypted at rest.
- D. A customer managed key is an optional choice for organizations that need full control over key policies and rotation; it is not required, since every table already defaults to encryption with an AWS-owned key.
- E. Switching the encryption key type is a table-level configuration change; DynamoDB continues to transparently encrypt and decrypt data regardless of which key type is used, so no application code changes are required.