Courseiva
Design of SAP Workloads on AWSmediumMultiple ChoiceObjective-mapped

PAS-C01 Design of SAP Workloads on AWS Practice Question

An SAP customer is using AWS KMS to encrypt EBS volumes for an SAP HANA database. The database administrator reports that the database is slow after enabling encryption. What is the MOST likely cause?

⚠ Common exam trap

The trap here is that candidates often attribute performance degradation to CPU overhead from encryption algorithms, but AWS KMS throttling is the real bottleneck because EBS encryption relies on API calls for key decryption, not on-instance cryptographic processing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The KMS API request rate limit is being exceeded, causing throttling.

When EBS volumes are encrypted, every I/O operation to the volume must call AWS KMS to decrypt the data key. If the database workload generates a high rate of these requests, it can exceed the KMS API request rate limit (default 5,500 requests per second per Region for symmetric keys), causing throttling and increased latency. This is the most likely cause of the observed slowdown after enabling encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The KMS key is not rotated frequently enough.

    Why it's wrong here

    Key rotation does not affect performance.

  • The KMS API request rate limit is being exceeded, causing throttling.

    Why this is correct

    High request rate can cause throttling and delays.

  • The EBS volume is not using the correct instance type for encrypted volumes.

    Why it's wrong here

    All instance types support encrypted volumes.

  • The KMS key is using a symmetric algorithm that degrades CPU performance.

    Why it's wrong here

    KMS encryption uses hardware acceleration, not CPU.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.