AWS Certified Data Engineer – AssociateData Storage and ManagementMedium

A data engineer is tasked with migrating an on-premises data warehouse to Amazon Redshift. The source data contains sensitive customer information and must comply with strict regulatory requirements for data at rest and in transit encryption. The solution must ensure that encryption keys are managed centrally and can be rotated automatically. Which Redshift encryption configuration best meets these requirements?

  1. AConfigure Redshift to use a hardware security module (HSM) for key management and disable SSL.
  2. BUse client-side encryption for all data before loading into Redshift and disable Redshift encryption.
  3. CEnable encryption at rest using AWS-managed keys and rely on default Redshift connection encryption.
  4. DEnable encryption at rest with AWS Key Management Service (KMS) and enforce SSL for all client connections.
Show answer & explanation

Correct answer: D. Enable encryption at rest with AWS Key Management Service (KMS) and enforce SSL for all client connections.

KMS provides centralized key management, automatic rotation, and integration with Redshift for at-rest encryption. Enforcing SSL ensures data in transit is encrypted, meeting both requirements.

Why the other options are wrong

  • A. Redshift does not directly integrate with external HSMs for key management; KMS is the standard. Disabling SSL is a major security vulnerability for data in transit.
  • B. Client-side encryption is complex to manage at scale and doesn't leverage Redshift's native encryption capabilities. Disabling Redshift encryption is a security risk.
  • C. AWS-managed keys offer less control and auditing compared to KMS customer-managed keys. Relying on default connection encryption might not be sufficient to 'enforce' SSL for all connections.

Redshift Encryption (KMS & SSL)

Amazon Redshift can encrypt data at rest using AWS KMS for key management and enforce SSL/TLS for data in transit, ensuring comprehensive protection for sensitive data.

  • Data at rest encrypted by default
  • Use KMS for customer-managed keys, rotation, and auditing
  • SSL/TLS for data in transit encryption
  • Crucial for regulatory compliance with sensitive data

Memory trick: KMS for rest, SSL for transit, keep data best.

More Data Storage and Management questions