AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A developer wants to understand how AWS KMS efficiently encrypts large objects without sending the entire object to the KMS service for direct encryption. Which encryption approach does AWS KMS use to accomplish this?
- AClient-side encryption using only the application's local library
- BDirect symmetric encryption of the full object using the customer master key
- CEnvelope encryption using a data key generated and encrypted by KMS
- DAsymmetric encryption of the entire object using a public/private key pair
Show answer & explanationAnswer & explanation
Correct answer: C. Envelope encryption using a data key generated and encrypted by KMS
KMS uses envelope encryption: it generates a unique data key, which is used locally to encrypt the actual data, and then the data key itself is encrypted by the KMS key (CMK) and stored alongside the ciphertext. This avoids sending large amounts of data to KMS directly, since the CMK never leaves KMS and only the small data key is encrypted/decrypted through the service.
Why the other options are wrong
- A. Pure client-side encryption without KMS involvement doesn't describe how KMS operates.
- B. KMS keys never directly encrypt large objects; they only encrypt data keys.
- D. KMS primarily uses symmetric encryption for this workflow, not asymmetric key pairs by default.
Envelope Encryption (KMS)
A technique where a data key encrypts the actual data locally, and the data key itself is then encrypted by a KMS master key, avoiding sending large data to KMS.
- KMS generates a plaintext and encrypted copy of the data key via GenerateDataKey
- The CMK never leaves the KMS service boundary
- Only the small encrypted data key needs to be decrypted by KMS to unlock the data
Memory trick: Put your letter in an envelope, then lock the envelope with the master key.