AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium
A global enterprise has a legacy application that stores sensitive customer data in a database. The company wants to migrate this database to Amazon RDS and ensure that all data at rest is encrypted using customer-managed encryption keys (CMKs) with strong auditability and control over key usage. The security team requires that the encryption keys are never exposed outside of AWS KMS. Which encryption solution should be implemented?
- AUse Amazon RDS encryption with AWS managed keys (CMKs).
- BUse Amazon RDS encryption with AWS owned keys.
- CUse Amazon RDS encryption with customer managed keys (CMKs) in AWS KMS.
- DImplement application-level encryption for data before it's stored in RDS.
Show answer & explanationAnswer & explanation
Correct answer: C. Use Amazon RDS encryption with customer managed keys (CMKs) in AWS KMS.
Using Amazon RDS encryption with customer managed keys (CMKs) in AWS KMS provides the required control, auditability, and assurance that the keys are managed within AWS KMS and never exposed. This meets the security team's requirement for strong key management.
Why the other options are wrong
- A. AWS managed keys (CMKs) are managed by AWS on your behalf; while they are CMKs, the customer has less direct control and auditability compared to customer-managed CMKs.
- B. AWS owned keys provide encryption but no customer control or auditability over the keys.
- D. Application-level encryption adds complexity to the application and may not be necessary when RDS offers robust, managed encryption with CMKs.
KMS Customer Managed Keys (CMKs)
Encryption keys created, owned, and managed by the customer within AWS Key Management Service (KMS), offering granular control and auditability.
- Customer has full control over key policies and permissions.
- Supports automatic key rotation.
- Provides detailed audit logs via AWS CloudTrail.
Memory trick: CMKs are your personal vault keys, you control who uses them and when.