AWS Certified Data Engineer – AssociateData Storage and ManagementMedium

A financial services company needs to store highly sensitive customer transaction data in an Amazon S3 data lake. This data must be encrypted at rest and in transit to meet stringent compliance requirements. They prefer to have full control over the encryption keys and require integration with AWS CloudTrail for auditing key usage. Which encryption method should the data engineer implement for the S3 objects?

  1. AServer-Side Encryption with AWS KMS keys (SSE-KMS)
  2. BClient-Side Encryption with a customer master key (CMK) stored in AWS KMS
  3. CServer-Side Encryption with S3-managed keys (SSE-S3)
  4. DServer-Side Encryption with Customer-provided keys (SSE-C)
Show answer & explanation

Correct answer: A. Server-Side Encryption with AWS KMS keys (SSE-KMS)

SSE-KMS provides server-side encryption using keys managed by AWS Key Management Service (KMS). This allows the customer to have control over the keys (e.g., key policies, rotation), integrates with CloudTrail for auditing key usage, and still offloads the encryption/decryption process to AWS S3, satisfying both security and operational requirements.

Why the other options are wrong

  • B. Client-Side Encryption (CSE) encrypts data before sending it to S3. While it offers maximum control, the question specifies server-side encryption (implied by 'S3 objects'), and CSE adds complexity to the application, which may not be necessary given SSE-KMS capabilities.
  • C. SSE-S3 uses keys managed entirely by AWS, offering no customer control over the keys or auditing of key usage through CloudTrail.
  • D. SSE-C requires the customer to provide and manage their own encryption keys, which are sent with each S3 request. While it gives control, it shifts more operational burden to the customer and doesn't inherently integrate with CloudTrail for key usage auditing.

S3 Encryption with KMS (SSE-KMS)

Server-Side Encryption for Amazon S3 objects using keys managed by AWS Key Management Service (KMS), providing customer control and auditing of encryption keys.

  • S3 encrypts objects server-side
  • Uses AWS KMS for key management
  • Customer controls KMS key policies and rotation
  • Key usage is auditable via AWS CloudTrail
  • Meets high compliance standards for data at rest

Memory trick: KMS gives you the 'Key Master' control for your S3 encryption.

More Data Storage and Management questions