AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityMedium
A security team requires that all data stored in Amazon EBS volumes attached to EC2 instances must be encrypted at rest. The SysOps Administrator needs to automate this for new volumes and ensure compliance. Which approach will meet this requirement with the least administrative effort?
- AEnable default EBS encryption for the AWS Region in which the volumes are created.
- BUse AWS Config rules to detect unencrypted volumes and remediate them with AWS Systems Manager Automation.
- CManually encrypt each new EBS volume using the AWS Management Console or CLI.
- DCreate an IAM policy that denies the creation of unencrypted EBS volumes.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable default EBS encryption for the AWS Region in which the volumes are created.
Enabling default EBS encryption for a region automatically encrypts all new EBS volumes and snapshot copies created in that region with a KMS key, significantly reducing administrative overhead and ensuring compliance for new resources.
Why the other options are wrong
- B. AWS Config can detect non-compliance, but remediation with Systems Manager adds complexity and is reactive, not proactive prevention.
- C. Manual encryption is time-consuming and prone to human error, not suitable for automation.
- D. An IAM policy can prevent creation but doesn't automatically encrypt; users would need to explicitly choose encryption, leading to potential errors or increased friction.
Default EBS Encryption
A regional setting that automatically encrypts all newly created EBS volumes and snapshot copies in that AWS Region, using a default KMS key or a specified custom KMS key.
- Applies to all new volumes and snapshot copies.
- Uses AWS managed key or customer managed key (CMK).
- Simplifies compliance with encryption-at-rest requirements.
- Does not affect existing unencrypted volumes.
Memory trick: Default encryption: Set it and forget it, for new volumes!