you are planning to build a fleet of ebs-optimized ec2 instances to handle the load of your new application. due to security compliance, your organization wants any secret strings used in the application to be encrypted to prevent exposing values as clear text. the solution requires that decryption events be audited and api calls to be simple. how can this be achieved? (select two)