AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium
A global enterprise has a legacy application that stores sensitive customer data in a database on an Amazon EC2 instance. The company's security policy requires that all sensitive data at rest and in transit must be encrypted with customer-managed keys, and these keys must be rotated annually. The current setup uses AWS-managed encryption keys for EBS volumes and S3 buckets. The company needs to implement a solution that provides full control over the encryption keys, allows auditability of key usage, and supports mandatory annual key rotation for all new and existing data stores. Which AWS service, combined with existing services, should a Solutions Architect recommend?
- AAWS Key Management Service (KMS) with Customer Managed Keys (CMKs).
- BAWS CloudHSM for hardware security module (HSM) based key storage.
- CAWS Certificate Manager (ACM) for SSL/TLS certificates.
- DAWS Secrets Manager for storing database credentials.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Key Management Service (KMS) with Customer Managed Keys (CMKs).
AWS Key Management Service (KMS) with Customer Managed Keys (CMKs) allows customers to create, control, and manage their own encryption keys. This provides full control over key usage, supports integration with various AWS services for data encryption, and enables features like automatic annual key rotation and detailed audit trails through AWS CloudTrail.
Why the other options are wrong
- B. CloudHSM provides FIPS 140-2 Level 3 validated hardware security modules for storing encryption keys. While it offers high assurance, it's more complex and expensive to manage than KMS CMKs and is typically used for the most stringent regulatory requirements where direct control over HSMs is mandated. KMS CMKs fulfill the requirement for 'customer-managed keys' without requiring direct HSM management, and support annual rotation and auditability more directly for general enterprise use cases.
- C. ACM manages SSL/TLS certificates for in-transit encryption (HTTPS) but does not provide customer-managed keys for data at rest or the ability to audit key usage or rotate them annually as required for data encryption keys.
- D. Secrets Manager is for storing and rotating secrets like database credentials, API keys, etc., not for managing encryption keys used to encrypt data at rest or in transit. It can use KMS CMKs to encrypt the secrets themselves, but it's not the primary service for data encryption keys.
KMS Customer Managed Keys (CMKs)
Encryption keys created and managed by an AWS customer within AWS Key Management Service (KMS), offering full control over key lifecycle, usage, and auditing.
- Customer retains full control over the key.
- Integrates with most AWS services for encryption.
- Supports automatic annual key rotation.
- Key usage can be audited via AWS CloudTrail.
Memory trick: KMS CMKs are your 'Personal Vault Keys' for AWS, giving you the master control.