AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global media company uses Amazon S3 to store large volumes of video content. They need to ensure that all data uploaded to an S3 bucket is encrypted at rest using server-side encryption with customer-provided encryption keys (SSE-C) to meet strict compliance requirements. How can the company enforce this encryption policy for all new objects uploaded to a specific S3 bucket?

  1. AUse AWS Key Management Service (KMS) to create a customer-managed key (CMK) and configure the S3 bucket to use this CMK for encryption.
  2. BImplement an AWS Lambda function that triggers on S3 PUT events, re-encrypting any unencrypted objects with SSE-C.
  3. CEnable default encryption for the S3 bucket and specify SSE-C as the encryption type.
  4. DConfigure a bucket policy that denies any PUT object request that does not include the 'x-amz-server-side-encryption-customer-algorithm' header.
Show answer & explanation

Correct answer: D. Configure a bucket policy that denies any PUT object request that does not include the 'x-amz-server-side-encryption-customer-algorithm' header.

To enforce SSE-C for all new objects uploaded to an S3 bucket, a bucket policy must be used. This policy denies any upload request that does not include the required SSE-C headers, effectively enforcing the encryption type.

Why the other options are wrong

  • A. This option describes SSE-KMS, not SSE-C. SSE-KMS uses AWS KMS CMKs for server-side encryption.
  • B. While a Lambda function could re-encrypt, it's a reactive approach and doesn't prevent unencrypted objects from being temporarily stored. A bucket policy is a proactive enforcement mechanism.
  • C. S3 default encryption supports SSE-S3 or SSE-KMS, but not SSE-C, which requires the client to provide the key during upload.

S3 Server-Side Encryption with Customer-Provided Keys (SSE-C)

SSE-C allows you to encrypt objects using your own encryption keys provided as part of the request. Amazon S3 manages the encryption and decryption process using the key you provide.

  • You manage and provide the encryption key.
  • S3 performs encryption/decryption server-side.
  • Requires specific HTTP headers for upload and download.

Memory trick: Keys in Hand, Policy in Place, S3 Stays Encrypted.

More Network Security, Compliance, and Governance questions