A global enterprise has a legacy application that stores sensitive customer data in a database on an EC2 instance. The database is encrypted using a self-managed key on the EC2 instance, which is cumbersome to rotate and audit. The enterprise wants to migrate this database to a fully managed service on AWS to improve security posture, simplify key management, and ensure compliance with regulatory requirements (e.g., GDPR, PCI DSS). Which solution should a solutions architect recommend for the database and key management?
- AMigrate the database to Amazon DynamoDB and enable default encryption at rest.
- BMigrate the database to Amazon Aurora and use client-side encryption with a custom key management solution.
- CKeep the database on EC2 and implement AWS Secrets Manager for key rotation.
- DMigrate the database to Amazon RDS and use server-side encryption with AWS KMS customer managed keys (CMKs).
Show answer & explanationAnswer & explanation
Correct answer: D. Migrate the database to Amazon RDS and use server-side encryption with AWS KMS customer managed keys (CMKs).
Migrating to Amazon RDS provides a fully managed database service, reducing operational burden. Using AWS KMS customer managed keys (CMKs) for server-side encryption allows centralized, auditable key management, automated rotation, and fine-grained access control, which is crucial for compliance and improved security posture.
Why the other options are wrong
- A. DynamoDB is a NoSQL database; if the legacy application uses a relational database, this would require a significant rewrite. While DynamoDB offers encryption at rest, using default encryption (AWS owned keys) offers less control and auditability compared to KMS CMKs, which is often preferred for strict compliance mandates.
- B. Amazon Aurora is a great managed relational database, but using 'client-side encryption with a custom key management solution' would reintroduce the operational complexity and auditing challenges that the enterprise is trying to avoid by moving away from 'self-managed key' solutions.
- C. Keeping the database on EC2 does not address the desire for a 'fully managed service' and 'reduced operational burden'. While Secrets Manager helps with secret rotation, it doesn't fully manage the encryption keys for the database itself or simplify the database management.
KMS Customer Managed Keys (CMKs)
AWS Key Management Service (KMS) enables you to create and manage cryptographic keys. Customer Managed Keys (CMKs) are KMS keys that you create, own, and manage, giving you full control over their lifecycle, including rotation, permissions, and auditing.
- You control the key lifecycle, including rotation.
- Integrates with many AWS services for encryption.
- Provides an audit trail of key usage in CloudTrail.
- Essential for strict compliance requirements (e.g., FIPS 140-2).
Memory trick: KMS CMKs are your 'Custom Master Keys' for data, giving you control and audits.