A highly regulated financial institution is deploying a new trading platform on AWS. Regulatory compliance mandates that all data at rest must be encrypted with customer-managed encryption keys (CMKs) and all data in transit must use TLS 1.2 or higher. The platform uses Amazon EC2 instances, Amazon S3 for data storage, and an Amazon RDS database. Which combination of actions will meet these encryption requirements?
- AEnable S3 default encryption for objects, use EBS encryption with AWS managed keys, and configure RDS with default encryption.
- BImplement AWS KMS for key management, use AWS Certificate Manager for TLS certificates, and configure Security Groups to allow only HTTPS traffic.
- CUse client-side encryption for S3 objects, enable EC2 instance store encryption, and configure RDS with storage-level encryption.
- DConfigure S3 bucket policies to enforce SSE-KMS with CMKs, enable EBS encryption with CMKs for EC2 volumes, activate RDS encryption with CMKs, and ensure all application endpoints use HTTPS/TLS 1.2+.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure S3 bucket policies to enforce SSE-KMS with CMKs, enable EBS encryption with CMKs for EC2 volumes, activate RDS encryption with CMKs, and ensure all application endpoints use HTTPS/TLS 1.2+.
To meet the 'data at rest with CMKs' requirement, S3 SSE-KMS with CMKs, EBS encryption with CMKs for EC2 volumes, and RDS encryption with CMKs must be explicitly configured. For 'data in transit with TLS 1.2 or higher', all application communication must use HTTPS/TLS 1.2+, which involves proper certificate configuration and endpoint setup.
Why the other options are wrong
- A. Uses AWS managed keys or default encryption, which does not meet the 'customer-managed encryption keys (CMKs)' requirement.
- B. While KMS and ACM are components, this option doesn't specify *how* they are used to encrypt data at rest with CMKs for all services, nor does it explicitly state TLS 1.2+ for application endpoints beyond just allowing HTTPS traffic.
- C. Client-side encryption for S3 doesn't cover all S3 access patterns, EC2 instance store is ephemeral and often not primary storage, and RDS storage-level encryption needs to specify CMKs.
Data Encryption in Transit & At Rest with CMKs
Ensuring all data, both stored and moving, is encrypted using customer-managed keys (CMKs) and secure protocols like TLS 1.2+.
- Data at rest: S3 SSE-KMS (CMKs), EBS Encryption (CMKs), RDS Encryption (CMKs).
- Data in transit: HTTPS/TLS 1.2+ for all communication.
- CMKs provide greater control over encryption keys.
- Critical for regulatory compliance (e.g., HIPAA, PCI DSS).
Memory trick: CMKs for rest, TLS for flight, secure data, morning, noon, and night.