passdrill
AWS SAA-C03 · EC2 & Compute · Card 031/038 medium

An account administrator enables the "Always encrypt new EBS volumes" (EBS encryption by default) setting in a Region, hoping this will secure the account's existing unencrypted volumes and snapshots too. What actually happens?

  1. The setting immediately re-encrypts every existing unencrypted volume and snapshot in that Region in the background
  2. The setting only applies going forward: newly created volumes and snapshots in that Region are encrypted automatically, but volumes and snapshots that already existed before the setting was enabled remain unencrypted unless the administrator explicitly migrates them
  3. The setting applies retroactively to existing volumes but not to existing snapshots
  4. The setting has no effect on snapshots at all in any case, only on volumes
Next card → Shuffle