CompTIA Cloud+ (CV0-004)SecurityEasy

A cloud security engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest. The company's compliance policy mandates that encryption keys must be managed entirely by the cloud provider, with no customer involvement in key generation, storage, or rotation. Which S3 encryption option meets this requirement?

  1. AServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
  2. BServer-Side Encryption with AWS Key Management Service (SSE-KMS)
  3. CServer-Side Encryption with Customer-Provided Keys (SSE-C)
  4. DClient-Side Encryption with AWS Key Management Service (CSE-KMS)
Show answer & explanation

Correct answer: A. Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)

SSE-S3 uses keys managed entirely by Amazon S3. AWS handles key generation, encryption, decryption, and rotation, aligning with the requirement for no customer involvement in key management.

Why the other options are wrong

  • B. SSE-KMS uses AWS KMS for key management, which allows for some customer control over key policies and usage, but not full provider management without customer involvement.
  • C. SSE-C requires the customer to provide and manage their own encryption keys.
  • D. CSE-KMS involves encrypting data on the client side before uploading, requiring customer management of the encryption process and potentially the keys.

SSE-S3

Server-Side Encryption where Amazon S3 manages both the encryption keys and the encryption process.

  • Easiest to implement.
  • No customer key management required.
  • Keys are unique and rotated regularly by AWS.

Memory trick: Who holds the key determines the encryption choice.

More Security questions