AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium
A global financial services company manages petabytes of sensitive customer data across various on-premises databases and file systems. They are currently using a homegrown encryption key management system that is difficult to audit, lacks robust key rotation policies, and does not meet new compliance requirements for data sovereignty and cryptographic module validation. The company needs to migrate this data to AWS, ensuring that all encryption keys are centrally managed, highly available, and auditable, while maintaining full control over key usage and access policies. Which AWS service and approach should be recommended to meet these requirements?
- AUse S3-managed encryption keys (SSE-S3) for all data stored in Amazon S3 and rely on AWS default key rotation for all other services.
- BMigrate all data to Amazon RDS and enable encryption at rest using the default RDS encryption, relying on AWS to manage the underlying keys.
- CImplement AWS Key Management Service (KMS) with Customer Managed Keys (CMKs) for all encryption operations, integrating it with AWS CloudTrail for auditing.
- DUse AWS Secrets Manager to store encryption keys and manually rotate them using a custom Lambda function.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement AWS Key Management Service (KMS) with Customer Managed Keys (CMKs) for all encryption operations, integrating it with AWS CloudTrail for auditing.
AWS KMS with Customer Managed Keys (CMKs) provides centralized, highly available, and auditable control over encryption keys, allowing the company to define key policies, rotation, and usage. CloudTrail integration ensures all key operations are logged for compliance.
Why the other options are wrong
- A. SSE-S3 uses AWS-managed keys, which do not provide the customer with full control over key policies, usage, or auditing required for stringent compliance. It also doesn't cover non-S3 data.
- B. While RDS encryption is good, using default RDS encryption means AWS manages the keys (AWS-owned or AWS-managed CMKs). The requirement is for the customer to maintain 'full control over key usage and access policies,' which points to CMKs in KMS, not default service encryption.
- D. AWS Secrets Manager is designed for managing secrets like database credentials, not primarily for cryptographic keys used for data encryption. While it can store keys, it lacks the full cryptographic lifecycle management, hardware security module (HSM) backing, and direct integration with AWS services for encryption that KMS provides.
AWS Key Management Service (KMS) with Customer Managed Keys (CMKs)
AWS KMS is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. CMKs are encryption keys that you create, own, and manage in KMS, giving you full control over their lifecycle.
- You control key policies, rotation, and permissions.
- Integrated with many AWS services for encryption.
- All key usage is logged in AWS CloudTrail for auditing.
Memory trick: KMS CMKs: Your keys, your rules, your audit trail.