AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global software company is developing a new application that processes highly sensitive customer financial data. The company has a strict policy that all encryption keys must be generated, stored, and managed in an external key management system (KMS) located outside of AWS. The application needs to encrypt data before it is uploaded to Amazon S3. Which method should the company use to meet this requirement?

  1. AClient-side encryption using a customer-managed encryption library that integrates with the external KMS.
  2. BAWS KMS Custom Key Store (CKS) integrated with an AWS CloudHSM cluster to store the keys.
  3. CServer-Side Encryption with Customer-Provided Keys (SSE-C).
  4. DServer-Side Encryption with AWS KMS (SSE-KMS) and a multi-Region key.
Show answer & explanation

Correct answer: A. Client-side encryption using a customer-managed encryption library that integrates with the external KMS.

Client-side encryption, where the encryption and decryption occur on the client application side, allows the use of an external key management system entirely outside of AWS. The customer's application encrypts the data using keys from their external KMS before sending it to S3, ensuring the keys never touch AWS infrastructure.

Why the other options are wrong

  • B. KMS Custom Key Store with CloudHSM stores keys within AWS (albeit in a dedicated HSM), which does not meet the 'external key management system located outside of AWS' requirement.
  • C. SSE-C requires the customer to provide the key with each S3 request, meaning the key is temporarily transmitted to S3, which might not fully satisfy the 'keys generated, stored, and managed in an external KMS located outside of AWS' without touching AWS.
  • D. SSE-KMS relies on AWS KMS to manage keys, which violates the 'external key management system located outside of AWS' requirement.

External Key Management (Client-Side Encryption)

Encrypting data on the client side using an encryption library that interfaces with an external Key Management System (KMS) located outside of AWS, ensuring that encryption keys never enter the AWS environment.

  • Keys are fully controlled and managed by the customer outside AWS.
  • Data is encrypted before transmission to AWS.
  • Provides the highest level of key sovereignty and data control.

Memory trick: External keys mean your data's safe, even before it hits the cloud wave.

More Domain 5: Data Protection questions