A pharmaceutical company is developing a new drug discovery platform that involves training highly sensitive machine learning models on patient genomic data. To meet stringent regulatory and security compliance, they need to ensure that all data used for training and inference is encrypted at rest and in transit, and that the encryption keys are managed and controlled by the company, not solely by AWS. Which AWS service combination provides the necessary encryption and key management capabilities for this scenario?
- AAmazon S3 with SSE-KMS and AWS KMS with customer managed keys (CMKs)
- BAmazon S3 with SSE-S3 and AWS KMS with AWS managed keys
- CAmazon EBS encryption with default KMS keys
- DAmazon S3 with SSE-C and AWS CloudHSM
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon S3 with SSE-KMS and AWS KMS with customer managed keys (CMKs)
To meet the requirement for company-controlled encryption keys, AWS Key Management Service (KMS) with Customer Managed Keys (CMKs) is essential. Amazon S3 Server-Side Encryption with KMS (SSE-KMS) allows S3 to encrypt data at rest using these CMKs. For data in transit, standard TLS/SSL encryption is used, which is implicitly handled when interacting with AWS services. This combination ensures company control over keys for data at rest and cryptographic protection in transit.
Why the other options are wrong
- B. AWS managed keys in KMS are managed by AWS, not controlled by the company, failing the key control requirement.
- C. Amazon EBS encryption with default KMS keys uses AWS managed keys, not customer-controlled keys, and primarily applies to EC2 volumes, not directly to S3 data where ML datasets are typically stored.
- D. SSE-C requires the customer to provide and manage their own encryption keys for each object, which is more cumbersome and less integrated than KMS CMKs for a large-scale ML platform. AWS CloudHSM provides dedicated hardware security modules, which is an even higher level of control but often overkill unless explicitly required, and SSE-C itself doesn't offer the same level of integrated key management as KMS CMKs.
Customer Managed Keys (CMKs)
Encryption keys created and managed by the customer within AWS Key Management Service (KMS), providing full control over key lifecycle and permissions.
- Customers define key policies and grant permissions.
- Provides an audit trail of key usage.
- Used with AWS services for data encryption at rest.
Memory trick: CMKs give YOU the key, not AWS.