AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy
A global enterprise collects and processes customer data from various regions worldwide. Due to strict data residency regulations in the EU, all data originating from EU customers must be stored and processed exclusively within the EU. The enterprise uses Amazon S3 for data storage and AWS Lambda for processing. How can the company ensure data residency for EU customer data?
- AImplement client-side encryption for all EU customer data before uploading to S3, regardless of the S3 bucket's region.
- BUse AWS PrivateLink to connect S3 buckets in any region to on-premises data centers located in the EU.
- CStore all EU customer data in an S3 bucket in a US region and apply a bucket policy that denies access from outside the EU.
- DUtilize an S3 bucket in an EU region (e.g., eu-west-1) and configure Lambda functions to run exclusively in the same EU region.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilize an S3 bucket in an EU region (e.g., eu-west-1) and configure Lambda functions to run exclusively in the same EU region.
To ensure data residency, both storage and processing must occur within the specified geographic region. Storing data in an S3 bucket in an EU region and configuring Lambda functions to execute within the same EU region ensures that the data and its processing remain within the EU boundaries, satisfying the regulatory requirement.
Why the other options are wrong
- A. Client-side encryption protects data confidentiality but does not guarantee data residency. The encrypted data still resides in the S3 bucket's physical location.
- B. AWS PrivateLink provides private connectivity to AWS services but does not dictate the physical location of the data or the processing. The S3 bucket's region is still paramount for residency.
- C. Storing EU data in a US region directly violates data residency requirements, regardless of access policies.
AWS Data Residency Enforcement
Ensuring that data is stored and processed exclusively within a specified geographic region to comply with local regulations, typically achieved by selecting appropriate AWS regions for resources.
- Involves selecting specific AWS regions for data storage and processing.
- Critical for compliance with regulations like GDPR.
- Affects where S3 buckets, EC2 instances, Lambda functions, etc., are provisioned.
Memory trick: Keep the data where the law says it needs to stay.