ETExamTower
Q4Design High-Performing Architectures

A company wants to migrate its application to a serverless solution. The serverless solution must analyze both existing and new data by using SQL. The company stores its data in an Amazon S3 bucket. The data must be encrypted at rest and replicated to another AWS Region. Which solution meets these requirements with the **LEAST** operational overhead?

← → navigate · a answer
Community votes
C
61% (11)
A
39% (7)
B
0% (0)
D
0% (0)
Discussion · 19
C 9
A - A new bucket + KMS multi-Region keys = Too much operational oversight. B - RDS is not a serverless solution C - By using the existing S3 bucket, you eliminate the need to create a new bucket and load data into it. D - Athena supports querying using SQL, so that rules out RDS.
A 7
A wins because it gives us encryption with AWS KMS multi-Region keys
A 5
Amazon S3 managed keys is region specific, for CRR, we must use KMS mult-region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html
A 4
Answer is A
A 3
A is correct
C 2
I will chose Option C for the following reasons: #1: Least operational overhead: Choosing "SSE-S3" over "SSE-KMS" minimizes operational overhead as it automatically manages encryption keys within S3, eliminating the need for additional KMS key management. #2: Existing S3 bucket: Reusing the existing bucket avoids the extra step of creating a new one and migrating data. #3: Athena for querying: Athena is a serverless solution ideal for querying large datasets stored in S3, aligning with the requirement for a serverless architecture.
2
For Option A: While using KMS multi-region keys provides more control, it adds extra management complexity compared to SSE-S3.
C 2
C is correct because it needs to replicate to different AWS region
C 2
It’s not require highly sensitive data or complexity gain permission. So it should use sse-s3 is suitable
A 2
A is correct. everyone. voting for c i think isnt paying attention to the part where you need the data replicated to a different region. how are you meant to replicate it without a new bucket? everyone saying use the existing bucket.... urm what? how can you replicate into the same bucket thats in the same region and expect it to be in a different region? clearly A.
C 2
The default encryption for S3 is SSE-S3, and cross-region replication can be enabled normally.
2
I checked AI, ChatGPT, Gemini , Claudi AI and DeepSeek think A is correct, but meta AI thinks C is correct. SSE-S3 is the default encryption, it will be least operational effort for sure. but with SSE-S3 (server-side encryption with S3-managed keys), AWS manages the encryption keys, and each region will use its own region-specific encryption key. There is no shared key between the source and destination buckets. AWS handles encryption and decryption seamlessly in each region. This approach is operationally simple but lacks control and consistency for encryption keys across regions.
C 2
The correct answer is C. Explanation: Option A: Incorrect. Although using AWS KMS multi-Region keys (SSE-KMS) and Amazon Athena to query the data meet the security and SQL querying requirements, creating a new S3 bucket and handling data migration increases operational overhead unnecessarily if the data already exists. Option C: Correct. Configuring Cross-Region Replication (CRR) on the existing S3 bucket makes efficient use of existing infrastructure and leverages server-side encryption with Amazon S3 managed keys (SSE-S3) to ensure data encryption at rest with lower operational complexity and costs compared to using KMS keys. Using Amazon Athena allows querying the data directly in S3, offering serverless and flexible SQL querying capabilities with minimal setup and operational overhead.
A 2
I would go on option A. Concidering this article: https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication-config-for-kms-objects.html If we just activate the replication on the existing bucket, the unencrypted data will by replicate unencrypted. If there was an option for creating a new bucket with crr, sse-s3 AND Athena I would have chosen this one. But the nearest solution is Wright en with rds instead of Athena. So go for A
C 2
Chat AI - Answer C - Configure CRR on the existing S3 bucket with SSE-S3 and use Amazon Athena to query the data. Serverless SQL: Athena is fully serverless and queries data directly in S3. Encryption at rest: SSE-S3 (S3-managed keys) satisfies encryption with zero KMS key management. Cross-Region Replication: CRR works seamlessly with SSE-S3. Least overhead: No new bucket, no data reload/migration, no KMS key creation/policies, and no databases to manage (unlike RDS).
C 2
we don't need to create a policy specifically for Amazon S3-managed keys (SSE-S3) to encrypt objects in your S3 bucket... should be more easy and LEAST operational overhead
A 1
S3 with SSE-KMS multi-Region keys + CRR + Athena meets all requirements with least overhead.
C 1
corrfect
C 1
C due to: Athena = Serverless SQL Amazon Athena allows you to run SQL queries directly against data in S3 without managing servers or databases. SSE-S3 = Lowest operational overhead SSE-S3 automatically encrypts objects at rest and requires no key management. CRR = Cross-Region replication S3 Cross-Region Replication automatically replicates objects to another AWS Region.