Auditors ask the grants team to confirm that the production Secrets Manager secret store protecting database credentials uses encryption at rest with an appropriate customer managed key policy. What should they verify?
Select an answer to reveal the explanation.
Short Explanation
Auditors want to see the vault's lock brand and who holds spare keys — Secrets Manager at rest under a CMK with a tight key policy, not plaintext mappings or Git souvenirs.
Full Explanation
Secrets Manager encrypts secrets at rest; production workloads should use a customer managed key with a key policy limited to intended application and administrator principals. Plaintext template mappings, Git copies, or disabling encryption undermine the control the auditors are validating.