AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A healthcare provider is storing sensitive patient data in Amazon S3. To meet HIPAA compliance, all data must be encrypted at rest. Furthermore, the encryption keys must be managed by the customer, and there must be an audit trail of key usage. Which encryption method and key management strategy should be implemented?

  1. AServer-Side Encryption with AWS Key Management Service (SSE-KMS) using a customer-managed key (CMK) in KMS.
  2. BServer-Side Encryption with Customer-Provided Keys (SSE-C) and regular key rotation.
  3. CServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3) with S3 Versioning enabled.
  4. DClient-Side Encryption with a customer-managed key (CMK) stored in AWS Key Management Service (KMS).
Show answer & explanation

Correct answer: A. Server-Side Encryption with AWS Key Management Service (SSE-KMS) using a customer-managed key (CMK) in KMS.

SSE-KMS with a customer-managed key (CMK) stored in AWS KMS meets the requirements. It encrypts data at rest, allows customer management of the encryption key (CMK), and AWS KMS provides an audit trail of all key usage through AWS CloudTrail.

Why the other options are wrong

  • B. SSE-C allows customer-provided keys, but it requires the customer to manage key storage and rotation outside of AWS KMS, and the audit trail for key usage is not directly provided by KMS.
  • C. SSE-S3 uses AWS-managed keys, which does not allow customer management or provide a direct audit trail of key usage by the customer.
  • D. Client-side encryption involves encrypting data before uploading, which is a valid strategy, but SSE-KMS provides server-side encryption with customer-managed keys and integrates seamlessly with S3 and CloudTrail for auditing.

SSE-KMS with Customer-Managed Keys (CMKs)

SSE-KMS uses AWS KMS to manage encryption keys. With a CMK, you have full control over key policy, rotation, and an audit trail of its usage through CloudTrail.

  • Data encrypted at rest in S3.
  • Keys managed in AWS KMS, controlled by customer.
  • Provides audit trail via CloudTrail for key usage.

Memory trick: HIPAA's Key Rule: KMS CMK for Audit and Control.

More Network Security, Compliance, and Governance questions