AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A security architect is designing a multi-account AWS environment for a new highly regulated application. They need to ensure that all data stored in Amazon EBS volumes attached to EC2 instances is encrypted by default. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS), and the policy must be enforced at an organizational level to prevent any non-compliant EBS volumes from being created. How can this be achieved?

  1. AUse IAM policies on EC2 roles to enforce EBS encryption with a CMK when instances are launched.
  2. BApply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.
  3. CImplement an AWS Config rule to detect unencrypted EBS volumes and trigger a Lambda function for remediation.
  4. DConfigure default encryption for EBS in each region for every account, using a specified CMK.
Show answer & explanation

Correct answer: B. Apply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.

To enforce preventive controls at an organizational level, an AWS Organizations Service Control Policy (SCP) is the most effective solution. An SCP can explicitly deny actions like 'ec2:RunInstances' or 'ec2:CreateVolume' if the request parameters do not include the necessary encryption configuration (e.g., KmsKeyId for a CMK or 'Encrypted': 'true' with a default CMK), ensuring that only compliant EBS volumes are created.

Why the other options are wrong

  • A. IAM policies control what specific users/roles can do. While useful, they can be bypassed by root users or administrators in child accounts, or simply misconfigured. An SCP provides a higher, unoverridable level of control across the organization.
  • C. AWS Config with Lambda is a detective and reactive control. It detects non-compliance after it occurs and then remediates, which is not a preventive measure to stop non-compliant volumes from being created.
  • D. While configuring default encryption for EBS in each account/region is good practice, it relies on manual configuration per account and doesn't prevent an override or misconfiguration. It's not a strong organizational-level enforcement.

EBS Encryption Enforcement with SCPs

AWS Organizations Service Control Policies (SCPs) can be used to prevent the creation of unencrypted EBS volumes or volumes not using a specified KMS CMK, enforcing encryption at rest as a preventive control across an entire organization.

  • SCPs are preventive, organization-wide guardrails.
  • Denies specific EC2 actions if encryption conditions are not met.
  • Ensures compliance with encryption-at-rest policies.

Memory trick: SCP's Iron Rule: Encrypted EBS, or No Creation at All.

More Network Security, Compliance, and Governance questions