A company stores sensitive data in an S3 bucket. The security team requires that all data be encrypted at rest and in transit. Which THREE measures should be implemented?
When accessing S3, using HTTPS (TLS/SSL) encrypts the data as it travels between the client and the S3 service endpoints. This prevents eavesdropping and man-in-the-middle attacks, ensuring the confidentiality and integrity of sensitive data during transmission over public networks. AWS S3 supports HTTPS by default, and it is a fundamental security best practice for protecting data in transit.
Why this answer
Exam trap
The trap here is that candidates may confuse client-side encryption as a bucket-level security measure, but it is an application-side implementation that does not enforce encryption at the S3 bucket level, and MFA Delete is a red herring unrelated to encryption requirements.