AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium

A global enterprise has a legacy application that stores sensitive customer data in a database running on an Amazon EC2 instance. The company has a strict compliance requirement to ensure that all data at rest is encrypted using keys that they fully control and can revoke at any time. They also need to integrate this encryption with their existing key management processes. Which AWS service and configuration should the Solutions Architect recommend to meet these requirements?

  1. AImplement client-side encryption within the application code before writing data to the database.
  2. BUse AWS Secrets Manager to store the database credentials and rely on default database encryption settings.
  3. CUse Amazon S3 server-side encryption with S3-managed keys (SSE-S3) for the database backups.
  4. DEncrypt the EC2 instance's EBS volumes using Customer Managed Keys (CMKs) in AWS Key Management Service (KMS).
Show answer & explanation

Correct answer: D. Encrypt the EC2 instance's EBS volumes using Customer Managed Keys (CMKs) in AWS Key Management Service (KMS).

Encrypting the EBS volumes attached to the EC2 instance using KMS Customer Managed Keys (CMKs) ensures that all data at rest on the volume (including the database) is encrypted. CMKs provide full control over the encryption keys, including the ability to revoke them, directly meeting the compliance requirement.

Why the other options are wrong

  • A. Client-side encryption is an option, but it adds complexity to the application code, requires managing encryption within the application, and might not be feasible for a legacy application with minimal changes.
  • B. Secrets Manager is for storing credentials, not for data at rest encryption. Default database encryption settings might use AWS-managed keys, which do not provide the full customer control required.
  • C. SSE-S3 uses AWS-managed keys, not customer-controlled keys, and only encrypts S3 objects (backups), not the active database on the EC2 instance.

KMS Customer Managed Keys (CMKs) for EBS Encryption

AWS Key Management Service (KMS) allows creating and managing encryption keys. Customer Managed Keys (CMKs) are encryption keys that you own and control, providing granular control over their lifecycle, permissions, and auditing. These can be used to encrypt EBS volumes.

  • CMKs provide full control over key rotation, permissions, and revocation.
  • Encrypting EBS volumes ensures data at rest encryption for EC2 instances.
  • Integrates with many AWS services for encryption.

Memory trick: KMS Keys Keep Kustomer Control.

More Continuously Improve Existing Solutions questions